⌘K in Inbox and search any threat or framework to find the rest.
Incident response
The runbooks you reach for when something is actively wrong — each walks the containment, communication, and recovery steps so nothing gets skipped under pressure.Phishing Triage
Assess a reported email and contain it if it’s malicious.
Account Takeover Runbook
Full response for a compromised account, start to finish.
Business Email Compromise Recovery
Work a BEC from detection through recovery and verification.
Ransomware Response
Contain, communicate, and coordinate recovery.
Session Token Theft Response
Revoke, re-secure, and confirm after stolen-session activity.
Zero-Day Emergency Response
Move fast on an unpatched, actively exploited vulnerability.
Identity and access
The proactive checks that close the gaps attackers use before they get used.Identity & MFA Health Check
Find identity and MFA gaps across a client tenant.
Global Admin Audit
Review who holds the keys and why.
Impossible Travel Runbook
Work an impossible-travel sign-in to a verdict.
MFA Fatigue Attack Response
Respond to push-bombing and re-secure the account.
Alerts and vendor signal
Turn the alert firehose into triaged, actionable tickets — and cut the noise that buries the real ones.Security Alert Response
A consistent first-response path for any security alert.
EDR Detection Runbook
Work an endpoint detection from alert to resolution.
DLP Alert Triage
Assess a data-loss alert and decide the response.
Security Noise Tuning
Cut false positives so real alerts stand out.
SOC operations
The rituals and briefs that keep a security desk coherent across shifts and clients.SOC Shift Handoff
Hand off open incidents and watch items cleanly.
SOC Classification Tree
Classify events consistently, every analyst the same way.
Security Incident Postmortem
Turn an incident into lessons and follow-up actions.
Monthly Security Report
Make a month of security work visible to clients.
Compliance and audit
The evidence, questionnaires, and framework prep that carry your posture through an assessment.Audit Prep Review
Get ready for an audit without the last-minute scramble.
SOC 2 Evidence Collection
Gather and organize evidence for a SOC 2 cycle.
Security Questionnaire & Vendor DDQ
Answer client security questionnaires and vendor due diligence.
HIPAA Safeguards Checklist
Walk the HIPAA safeguards for a covered client.
NIST CSF Gap Brief
Map a client against the CSF and surface the gaps.
Cyber Insurance Form Prep
Prep an accurate cyber-insurance application.
Next
That’s the bench. Head back to the hub for your starter kit and shift ritual, or browse the full library.Back to your course
Starter kit, SOC ritual, and the FAQ.
Browse the Skill Library
Hundreds of skills — search any threat or framework.