07 - References and Further Reading
Frameworks & Methodologies
- MITRE ATT&CK Framework: The global standard for understanding adversary tactics and techniques.
- SANS Incident Handler's Handbook: Core methodologies for Incident Response (PICERL).
- Sigma Rules: Generic signature format for SIEM systems.
- Wazuh (SIEM/XDR):
- Shuffle (SOAR):
- MISP (Threat Intelligence):
- CyberChef (Swiss Army Knife for Triage):
Recommended Reading & Reports
- SANS Annual SOC Survey: Insights into the challenges, metrics, and architectures of modern SOCs.
- Red Canary Threat Detection Report: Annual report detailing the top ATT&CK techniques observed in the wild.