Intermediate tools
Intermediate tools.
Choose one intermediate SOC tool. These tools focus on rule logic, MITRE mapping, triage thinking, timelines, and suspicious command analysis.
Suspicious Command Explainer
Explain commands like PowerShell encoded payloads, certutil downloads, net user changes, and persistence commands.
Sigma Rule Explainer
Paste a Sigma-style rule and see what it detects, what matched, false positives, and investigation steps.
MITRE ATT&CK Mapper
Paste an alert, command, or log and map it to likely tactics and techniques.
Alert Triage Assistant
Turn an alert into a clear SOC triage note with risk, matched evidence, and first checks.
Investigation Timeline Builder
Paste multiple logs and build a readable event timeline from earliest evidence to possible impact.