Initiative

InfoSec Stories

Practical cybersecurity knowledge from inside security operations, research, analysis, detection guidance and lessons learned, documented honestly and built to last.

InfoSec Stories is my initiative for sharing practical cybersecurity knowledge: the kind of material I wish had existed when I started in a 24/7 SOC. It collects research, project write-ups, detection guidance and lessons learned from years of security operations work into one growing body of work.

Why it exists

Most security content is either vendor marketing or theory. The gap in the middle, what logs to enable, how a detection actually behaves in production, what an incident response really looks like at 3 a.m., is where analysts live. InfoSec Stories is my attempt to document that middle ground honestly.

What it covers

  • Security operations and SOC practice
  • Detection engineering and logging guidance
  • Windows and Linux telemetry (Sysmon, PowerShell logging, event analysis)
  • Threat intelligence and threat hunting
  • Incident response frameworks and lessons learned

The stories

Articles & research

Detection Engineering2 min read

PowerShell Logging for Blue Teamers

Module logging, script block logging and transcription, the three PowerShell logging layers every blue team should enable, and what each one actually catches.

Detection Engineering2 min read

Enhancing Threat Detection with Microsoft Sysmon

Why Sysmon remains the highest-value free telemetry on Windows, the events that matter, configuration philosophy, and detections to build first.

More writing lives on the blog and on Medium.

Connected work

Projects & lessons behind the stories

  • Threat Hunting Research

    Hypothesis-driven hunts across client environments, including research into detection bypass techniques in Active Directory and how to close those gaps.

  • Windows Event Logging / What2Log

    Practical guidance on which Windows events actually matter for defenders, audit policy, Sysmon and PowerShell logging configuration for detection.

  • SOC Maturity Research

    Research into building, measuring, and scaling highly effective security operations from the inside out.