Resources

Tools & resources for SOC analysts

Operational tools and resources for phishing investigation, Threat Hunting workflows, triage automation and reusable SOC methods.

Featured SOC tool

ThePhishAnalyzer

ThePhishAnalyzer is the primary resource in this portfolio: a workbench designed to accelerate suspicious-message analysis and produce an analyst-ready summary. The other resources complement this work with investigation workflows and structured technical-learning support.

A phishing-investigation workbench for SOC analysts: EML/RFC822 parsing, SPF/DKIM/DMARC checks, URL extraction, enrichment and analyst-ready summaries.

SOC AutomationPhishing AnalysisOSINTTypeScript

A SOC resource should accelerate a decision

I design these resources as working aids: they structure the data to verify, make the process repeatable and show what must remain under analyst control. For phishing, that means preserving headers, sender identity, authentication results, URLs, attachments and business context before reaching a conclusion. For Threat Hunting, the priority is to connect a hypothesis to available data sources, queries, observations and remediation decisions. Each resource is intended to support a defensible investigation rather than produce an opaque automated verdict.

Lead Magnet #01

The Ghost-Hunter workflow map

A clear view of the Ghost-Hunter pipeline to move from raw HTTP traffic to actionable test hypotheses, then to properly tracked findings.

CaptureReductionTriageExecution
Resource page / live capture
Lead Magnet #02

CISSP Study Planner

An interactive planner that turns your exam horizon, weekly bandwidth and study rhythm into a concrete CISSP plan across all 8 domains.

TimelineLoadCadenceTracking
Resource page / live capture
Lead Magnet #03

LLM SOC Detection Starter Pack

5 scenarios to monitor, the signals to correlate and the first detection priorities to stand up on an LLM stack.

ScenariosSignalsIdentityAsset
Resource page / live capture
Published resource

Top 6 Claude Cowork Security Risks to Watch

Spot deployments, enforce MCP allowlists, and monitor scheduled tasks to catch stealthy prompt injections and session hijacks.

paragraphsbullet-listsequence-previewcapture
Resource page / live capture
Published resource

RAG Pipeline Tool-Guard Checklist

Sanitize retrieved chunks and audit each segment before tool execution to stop unauthorized commands and data leaks.

paragraphsbullet-listsequence-previewcapture
Resource page / live capture
Published resource

Indirect Prompt Injection Control Checklist

A practical way to stop poisoned web pages, emails, and documents from steering your agent’s actions.

paragraphsbullet-listsequence-previewcapture
Resource page / live capture
Published resource

AI Agent Access Control Workbook

Reduce AI agent risk with a practical workbook for separating high-risk capabilities, enforcing access controls and auditing every action.

paragraphsbullet-listsequence-previewcapture
Resource page / live capture
Published resource

Weekly AI Security Testing Drill

A repeatable method to move from bookmarking tools to running tests, adding controls, and keeping evidence.

paragraphsbullet-listsequence-previewcapture
Resource page / live capture
Published resource

A Jagged Frontier Evaluation Kit for Security AI

A repeatable way to test models on your real security tasks and choose the workflow that produces validated results.

paragraphsbullet-listsequence-previewcapture
Resource page / live capture