Tools & resources for SOC analysts
Operational tools and resources for phishing investigation, Threat Hunting workflows, triage automation and reusable SOC methods.
ThePhishAnalyzer
ThePhishAnalyzer is the primary resource in this portfolio: a workbench designed to accelerate suspicious-message analysis and produce an analyst-ready summary. The other resources complement this work with investigation workflows and structured technical-learning support.
A phishing-investigation workbench for SOC analysts: EML/RFC822 parsing, SPF/DKIM/DMARC checks, URL extraction, enrichment and analyst-ready summaries.
A SOC resource should accelerate a decision
I design these resources as working aids: they structure the data to verify, make the process repeatable and show what must remain under analyst control. For phishing, that means preserving headers, sender identity, authentication results, URLs, attachments and business context before reaching a conclusion. For Threat Hunting, the priority is to connect a hypothesis to available data sources, queries, observations and remediation decisions. Each resource is intended to support a defensible investigation rather than produce an opaque automated verdict.
The Ghost-Hunter workflow map
A clear view of the Ghost-Hunter pipeline to move from raw HTTP traffic to actionable test hypotheses, then to properly tracked findings.
CISSP Study Planner
An interactive planner that turns your exam horizon, weekly bandwidth and study rhythm into a concrete CISSP plan across all 8 domains.
LLM SOC Detection Starter Pack
5 scenarios to monitor, the signals to correlate and the first detection priorities to stand up on an LLM stack.
Top 6 Claude Cowork Security Risks to Watch
Spot deployments, enforce MCP allowlists, and monitor scheduled tasks to catch stealthy prompt injections and session hijacks.
RAG Pipeline Tool-Guard Checklist
Sanitize retrieved chunks and audit each segment before tool execution to stop unauthorized commands and data leaks.
Indirect Prompt Injection Control Checklist
A practical way to stop poisoned web pages, emails, and documents from steering your agent’s actions.
AI Agent Access Control Workbook
Reduce AI agent risk with a practical workbook for separating high-risk capabilities, enforcing access controls and auditing every action.
Weekly AI Security Testing Drill
A repeatable method to move from bookmarking tools to running tests, adding controls, and keeping evidence.
A Jagged Frontier Evaluation Kit for Security AI
A repeatable way to test models on your real security tasks and choose the workflow that produces validated results.
