Resources

Detection packs & triage sheets

Things to deploy and things to print. Everything here carries a date and a version, because a detection rule with no date on it cannot be tuned: you cannot tell whether the false positives you are seeing were budgeted for or arrived with a product update.

Deployable rule packs

Sigma, YARA and Snort, published as dated packs. Every rule ships with its false-positive notes, because a rule deployed without them is a rule that gets switched off in a fortnight.

One-page triage sheets

Built for a printer and for somebody who is standing up. These are pages rather than PDF binaries on purpose: when an event ID moves on a new build, a PDF on a desk stays wrong forever and a page can be corrected.

PDF • 1-PAGE A4 • PRINT-READY

Active Directory Compromise Triage

You have credible reason to believe a domain account has been compromised, or that someone has domain-level access they should not have.

  1. 1.Establish scope, before you change anything
  2. 2.Collect, in this order
  3. 3.Containment that does not tip off the operator
  4. 4.The two resets, in order

Updated 2026-09-01

PDF • 1-PAGE A4 • PRINT-READY

Windows Host Triage, First 60 Minutes

One Windows host is suspect. You have access, and you do not yet know whether it is compromised, what it ran, or whether anything is still live on it.

  1. 1.Volatile first, in this order
  2. 2.Execution evidence
  3. 3.Persistence, the five that cover most of it
  4. 4.Logs worth pulling before they roll

Updated 2026-09-01

PDF • 1-PAGE A4 • PRINT-READY

Ransomware, First Hour

Files are encrypting now, or encryption has stopped and you do not yet know whether the operator is still in the estate.

  1. 1.Stop the spread, without destroying evidence
  2. 2.Capture while it is still there
  3. 3.Find the entry, it is usually one of these
  4. 4.Before anyone says the word "restore"

Updated 2026-09-01