Resources
// 24 links in 6 categories, all of them somebody else's work
ThreatIntel4// What is actually being exploited, and who is doing it.
KqlReferences4// Language docs and schema references worth keeping open in a tab.
DetectionEngineering4// Frameworks and rule sets for writing detections that survive review.
Dfir4// Forensics and incident response tooling.
TrainingAndCerts4// Hands-on practice, weighted towards blue team.
Tools4// Things to paste an artefact into at two in the morning.