Blue Team Toolkit¶
The Blue Team Toolkit is a field reference for defensive security work: incident response, log analysis, phishing analysis, network analysis, endpoint forensics, malware triage, and hardening. It is maintained by @EvolvingSysadmin.
The content comes from hands-on work as a security administrator, lab work, and training including Security Blue Team's BTL1.
Start Here¶
The Playbooks are how I put the rest of this toolkit to work: step-by-step procedures for responding to incidents, triaging alerts, hunting, and handling urgent vulnerabilities.
Sections¶
| Section | What's Inside |
|---|---|
| Playbooks | Incident response, alert triage, threat hunting, and operations procedures |
| Incident Response | The lifecycle: preparation, detection and analysis, containment, and post-incident work |
| Threat Intelligence | MITRE ATT&CK tactics and techniques with detection and mitigation notes |
| SIEM and Log Analysis | Windows, Linux, web server, and network device logs; Sysmon, Splunk, DeepBlueCLI |
| Phishing and Email | Email protocols, sender authentication, and header analysis |
| Network Analysis | Network commands, common ports, Nmap, and Wireshark |
| Endpoint Forensics | Evidence handling, Windows and Linux artifacts, memory, and forensic tools |
| Malware Analysis | YARA |
| Hardening | Active Directory |
How Pages Are Organized¶
- Reference pages explain why a topic matters, give the reference data in tables, and describe how I use it
- Tool pages cover when I reach for the tool, installation, common tasks, and how to read the output
- Pages link to the playbooks and related pages that use them
The source is on GitHub.
