Skip to content

Blue Team Toolkit

The Blue Team Toolkit is a field reference for defensive security work: incident response, log analysis, phishing analysis, network analysis, endpoint forensics, malware triage, and hardening. It is maintained by @EvolvingSysadmin.

The content comes from hands-on work as a security administrator, lab work, and training including Security Blue Team's BTL1.

Start Here

The Playbooks are how I put the rest of this toolkit to work: step-by-step procedures for responding to incidents, triaging alerts, hunting, and handling urgent vulnerabilities.

Sections

Section What's Inside
Playbooks Incident response, alert triage, threat hunting, and operations procedures
Incident Response The lifecycle: preparation, detection and analysis, containment, and post-incident work
Threat Intelligence MITRE ATT&CK tactics and techniques with detection and mitigation notes
SIEM and Log Analysis Windows, Linux, web server, and network device logs; Sysmon, Splunk, DeepBlueCLI
Phishing and Email Email protocols, sender authentication, and header analysis
Network Analysis Network commands, common ports, Nmap, and Wireshark
Endpoint Forensics Evidence handling, Windows and Linux artifacts, memory, and forensic tools
Malware Analysis YARA
Hardening Active Directory

How Pages Are Organized

  • Reference pages explain why a topic matters, give the reference data in tables, and describe how I use it
  • Tool pages cover when I reach for the tool, installation, common tasks, and how to read the output
  • Pages link to the playbooks and related pages that use them

The source is on GitHub.

Happy Defending!