TOOLS

The blue-team toolbox

A working directory of SOC tooling — what I run in production, and what I have taken apart to find out whether it earns a place. Grouped by what it costs you, because that is the first question anyone building a SOC actually has to answer. Every entry links straight to the vendor.

30
IN THE DIRECTORY
STATUS
OPERATEDrun in production
EXPLOREDworth knowing, not run in anger
01ENTERPRISE SOLUTIONS23 TOOLS · ALL OPERATED · LINKS OUT
SIEM
Microsoft Sentinel
Detection rules, the incident queue and hunting queries, all in KQL.
OPERATEDOfficial site ↗
SIEM
Splunk
Search and correlation across log sources.
OPERATEDOfficial site ↗
XDR
Microsoft Defender XDR
The single pane incidents are actually worked from.
OPERATEDOfficial site ↗
EDR
Defender for Endpoint
Endpoint detection, onboarding and live response actions.
OPERATEDOfficial site ↗
EDR
CrowdStrike Falcon
Endpoint policy, host containment and threat telemetry.
OPERATEDOfficial site ↗
IDENTITY
Microsoft Entra ID
Directory, conditional access and sign-in telemetry.
OPERATEDOfficial site ↗
IDENTITY
Entra ID Protection
Risky user and risky sign-in detections.
OPERATEDOfficial site ↗
PRIVILEGE
Entra Privileged Identity Management
Just-in-time elevation — the tool that removes standing privilege.
OPERATEDOfficial site ↗
PRIVILEGE
Microsoft PAM
Privileged access requests and approval workflow.
OPERATEDOfficial site ↗
IDENTITY
Defender for Identity
On-premises Active Directory attack detection.
OPERATEDOfficial site ↗
DATA
Microsoft Purview DLP
Policies that stop exfiltration across cloud and endpoint channels.
OPERATEDOfficial site ↗
DATA
Purview Insider Risk
Behavioural policies for data misuse by people already inside.
OPERATEDOfficial site ↗
CLOUD
Microsoft Azure
The estate the rest of the stack runs in.
OPERATEDOfficial site ↗
CLOUD
Microsoft 365 Security
Tenant-level posture and security configuration.
OPERATEDOfficial site ↗
ENDPOINT
Microsoft Intune
Device enrolment, compliance baselines and policy.
OPERATEDOfficial site ↗
VULN
Qualys
Authenticated scanning, and coordinating the patch cycle behind it.
OPERATEDOfficial site ↗
VULN
Defender Vulnerability Management
Exposure tracking inside the Defender estate.
OPERATEDOfficial site ↗
EMAIL
Defender for Office 365
Phishing investigation — headers, sender reputation, URLs, attachments.
OPERATEDOfficial site ↗
EMAIL
Forcepoint ONE ESG
Email security gateway: policy, quarantine and release.
OPERATEDOfficial site ↗
WEB
Forcepoint ONE WSG
Web filtering and egress policy.
OPERATEDOfficial site ↗
PERIMETER
Cloudflare
WAF rules and edge protection.
OPERATEDOfficial site ↗
AUTOMATION
Azure Logic Apps
Incident-response playbooks wired to alert triggers.
OPERATEDOfficial site ↗
AUTOMATION
Copilot for Security
Investigation summaries and first drafts of the write-up.
OPERATEDOfficial site ↗
02OPEN SOURCE4 TOOLS · THE GROWTH AREA
03OPERATIONS & DOCUMENTATION3 TOOLS · NOT SECURITY TOOLS
04CONTACTALEPPO · UTC+3

Something missing?
Tell me what to add.

This directory is only as good as what is in it. If a tool earns its place and is not here, say so — and say why.

ELSEWHERE
OPEN TO ROLES
contact@yousef-fallaha.com
Write to me→
WORKINGRemote · Aleppo
NOWSOC Lead, Omarino IT Services