Blue Team & DFIR · Red Team & Offensive Security · Purple Team
A practical, community-oriented reference guide covering detection & response, offensive security, and the purple team practice that connects them. Written to give beginners a structured entry point into the field, and dense enough to stay useful as a day-to-day reference once you're operating in a SOC, a DFIR team, or on a pentest engagement.
- SOC fundamentals & analyst triage workflow
- Core log sources: Windows Security Event IDs, Sysmon event IDs, DNS/proxy/EDR/cloud logs
- Incident Response lifecycle (PICERL)
- Digital forensics: Windows live-triage tooling and key artifacts (Prefetch, Amcache, Shimcache, Shellbags, MFT, USN Journal, UserAssist)
- Malware triage & sandboxing, plus threat intelligence news sources
- Endpoint hardening & personal privacy toolkit
- Useful web services for analysts
- OSINT for defenders: attack surface management, breach exposure monitoring, phishing & brand abuse detection, threat infrastructure tracking
- Reconnaissance & enumeration: OSINT recon (theHarvester, Amass/Subfinder, Shodan/Censys, crt.sh, Hunter.io, GitHub dorking, Google dorking, Maltego/SpiderFoot/Recon-ng), Nmap, Gobuster
- Web application attacks (XSS, SQL injection, SQLMap, WPScan)
- Network attacks & sniffing
- Exploitation, payloads & C2 frameworks
- SMB / Windows network exploitation
- Privilege escalation (Linux & Windows)
- PowerShell, Active Directory enumeration & post-exploitation
- Active Directory attacks: LLMNR/NTLM relay, password spraying, AS-REP roasting, Kerberoasting, Mimikatz (Pass-the-Hash/Ticket/Key), DCSync, Golden/Silver Tickets, delegation abuse (unconstrained/constrained/RBCD), ACL abuse & BloodHound, AD CS (Certipy/ESC1) abuse, trust & GPO abuse, plus an AD pentest tooling cheat sheet (Impacket, NetExec, Rubeus, Certipy, BloodHound)
- Credential attacks (John the Ripper, Hashcat, wordlists, phishing)
- What purple teaming actually is, and how it differs from a standard pentest
- CTI-driven threat & technique selection, plus OSINT & infrastructure intelligence (MITRE ATT&CK Groups, URLhaus/ThreatFox, JARM/JA3 fingerprinting, attack surface parity checks)
- The purple team engagement methodology, step by step
- Adversary emulation & exercise formats: tabletop, single-technique validation, full adversary emulation, breach & attack simulation (BAS), objective-based red team
- Frameworks & tooling: MITRE ATT&CK Navigator, Atomic Red Team, Caldera, Sigma, DeTT&CT
- The detection engineering loop
- Metrics that matter (MTTD, MTTR, validated ATT&CK coverage)
- A worked example: Kerberoasting from emulation to a shipped detection rule
Anyone starting out in cybersecurity who wants a structured map of the field, and practitioners who want a dense reference they can come back to. The Blue Team section is deliberately built around real SOC/DFIR practice — log sources, detection logic, forensic artifacts — rather than a generic list of privacy tools.
Everything in Part II is documented for authorized security testing only: engagements you are contractually and explicitly permitted to run (pentests, red/purple team exercises, your own lab, licensed platforms such as TryHackMe/HackTheBox). Running these techniques against systems you do not own or are not authorized to test is illegal in most jurisdictions.
This guide is meant to keep growing. If you spot something outdated, missing, or worth adding — especially real-world blue team / DFIR experience — issues and pull requests are welcome.
Curated and maintained by Enzo Demaretz — Security Engineer, CTI/DFIR Analyst & Purple Team practitioner.