Security operations
Compliance & posture
Posture work is detection work done in advance. Every failing configuration control is either a detection you will need later or an alert you will never receive. Read this page as a list of future incidents you can cancel.
Secure configuration baseline
Servers & workstations · 3 sampled controls
| Control | Requirement | Status | Failing hosts |
|---|---|---|---|
| 1.2.4 | Enforce script-block logging on all endpoints Enable script-block and module logging via policy, then confirm events reach the pipeline. | Fail | 4 / 10 |
| 2.3.1 | Disable legacy authentication protocols Remove legacy protocol support on identity servers and monitor for fallback attempts. | Fail | 2 / 6 |
| 5.1.9 | Restrict local administrator group membership | Pass | 0 / 10 |
Overall posture
78%
pass rate across sampled controls
Turn a failing control into work
The loop that actually moves the score.
- 1. Confirm the finding. Automated checks misfire on unusual builds — verify one host manually.
- 2. Name the owner. Controls fail because nobody owns the setting, not because nobody knows about it.
- 3. Ship a detection meanwhile. If legacy authentication cannot be disabled this quarter, alert on its use today.
- 4. Re-check and record. Evidence with a timestamp is what an audit accepts; a screenshot is not.
Why compliance scores mislead on their ownjudgement›
A rising score can mean better security or a narrower scope. Always report the score with its denominator and its direction over time, and call out the small number of controls that carry most of the real risk — logging completeness, privileged access, and authentication strength. Ten cosmetic passes do not offset one estate without script logging.
Controls that directly feed detection qualitylinks›
- Command-line and script-block logging — without it, execution detections cannot be written at all.
- Audit policy for privileged actions — the backbone of credential-access detection.
- Time synchronisation — timelines built from unsynchronised clocks are unusable in an investigation.
- Log forwarding on every asset class — the gap between “deployed” and “reporting” is where breaches live.
Learn this capability
Hands-on labs that build the technique behind this workspace. Skills transfer to any mainstream SIEM.
Advanced · Assessment · 25 min
Executive incident briefing
Assessment. INC-1041 is contained. The executive team wants a five-minute briefing: what happened, what it means for the business, and what changes.
Advanced · Theory · 20 min
SOC metrics that matter
You report to the CISO monthly. Choosing the wrong metrics drives the wrong analyst behaviour.
Intermediate · Theory · 16 min
Detection quality principles
You own the detection catalogue. Every rule you deploy costs analyst attention, so quality is measured in outcomes, not count.