OODA Loop: The Security Operations Framework
Observe, Orient, Decide, Act: how a fighter-pilot decision framework maps onto SOC monitoring, triage and incident response, and why tempo wins.
Read the article →Field Notes
Practical writing on security operations, what to log, what to detect, and how defenders actually win.
Featured article
Observe, Orient, Decide, Act: how a fighter-pilot decision framework maps onto SOC monitoring, triage and incident response, and why tempo wins.
Read the article →All articles
The most repeated line in security is only half true. Where the asymmetry cliché breaks down, and how defense-in-depth flips it back on the attacker.
How attackers evade common Active Directory detections, and the audit policy, telemetry and mitigation changes that take those blind spots away.
Module logging, script block logging and transcription, the three PowerShell logging layers every blue team should enable, and what each one actually catches.
Sysmon is no longer Windows-only. What Sysmon for Linux captures, how to deploy it, and where it fits next to auditd in a monitoring stack.
Not all logs are equal. How to prioritize log sources during a SIEM implementation so the SOC gets detection value first, not just volume.
RDP remains a favorite path for attackers. The Windows event IDs that reconstruct an RDP session from connection to disconnect, and the detections to build on them.
What threat intelligence actually is, the difference between strategic, operational and tactical intelligence, and how a SOC turns feeds into decisions.
Why Sysmon remains the highest-value free telemetry on Windows, the events that matter, configuration philosophy, and detections to build first.
No articles match.
Medium archive
Everything I've published on Medium, each preview links to the full article at shreenkhalabhattarai.medium.com.
Reflections on accelerating action for gender equality in cybersecurity and beyond.
Read on Medium ↗
Applying the Observe–Orient–Decide–Act loop to security operations, a framework for faster, better decisions in the SOC.
Read on Medium ↗
Unpacking the asymmetry cliché, what it gets right, what it gets wrong, and what it means for how defenders should think.
Read on Medium ↗
How attackers evade common Active Directory detections, and the logging and mitigation strategies that close the gaps.
Read on Medium ↗
Building a robust PowerShell logging pipeline, module logging, script block logging and transcription for effective monitoring and detection.
Read on Medium ↗
Deep insights into processes and activities on Linux hosts with Microsoft's Sysmon for Linux.
Read on Medium ↗
SIEM is essential to a strong security strategy, but only if the right log sources are prioritized. A practical prioritization guide.
Read on Medium ↗
Within the SOC, visibility is everything. Reading RDP events to reconstruct sessions and catch lateral movement.
Read on Medium ↗
Turning the telescope outward, what threat intelligence is and how it informs defensive decisions.
Read on Medium ↗
Using Sysmon's rich Windows telemetry to detect increasingly sophisticated threats.
Read on Medium ↗
Certifications and learning resources for building a career in security operations. Published in the CryptoGen Nepal publication.
Read on Medium ↗