Published objectives
| Objective | Revision topic |
|---|---|
| 1.1 · Security platform architecture | 01 Platform architecture and access |
| 1.2 · Platform and data access | 01 Platform architecture and access |
| 2.1 · Log ingestion and parsing | 02 Ingestion, normalization and entity context |
| 2.2 · Entity context and enrichment | 02 Ingestion, normalization and entity context |
| 3.1 · Hypothesis-led hunting | 03 Threat hunting and retroactive analysis |
| 3.2 · Threat intelligence and retrohunt | 03 Threat hunting and retroactive analysis |
| 4.1 · Detection design and risk | 04 Detection engineering and tuning |
| 4.2 · Intelligence-driven detection tuning | 04 Detection engineering and tuning |
| 5.1 · Containment and investigation | 05 Incident response and safe automation |
| 5.2 · Response playbooks | 05 Incident response and safe automation |
| 5.3 · Case lifecycle | 05 Incident response and safe automation |
| 6.1 · Dashboards and reports | 06 SOC health and meaningful reporting |
| 6.2 · Health and silent-source monitoring | 06 SOC health and meaningful reporting |