Navigation
Learn · Free Guides

Learn / the concepts.

The reasoning behind the tools, in plain English.

mlab publishes four kinds of reference, and they answer different questions. Picking the wrong one is why documentation feels useless.

You are choosing between two things
The comparisons below. Each one ends with a verdict rather than a shrug.
You need a value you will forget again in five minutes
A cheat sheet. Ports, status codes, regex tokens, all in one scroll.
You hit a term in a report and it meant nothing
The glossary: 122 definitions, most linked to the tool that operates on the thing.
You want to understand a practice, not a word
The blog. Longer, written by people doing the work.

Guides from the blog

How to Read a CTI Report Like an Analyst (Not a Journalist) Vendor threat reports mix marketing, narrative, and actionable intelligence. A repeatable method for extracting IOCs, TTPs, and detection opportunities while filtering the noise. threat intelligence · 5 min read STIX, TAXII, MISP: A Field Guide to Threat Intel Sharing Formats What STIX objects, TAXII transport, and the MISP platform each actually do, where interoperability breaks in practice, and when a plain CSV is all the standard you need. threat intelligence · 6 min read Passive DNS for Investigators: Tracking Infrastructure Through Time Attackers rotate infrastructure constantly, but DNS remembers. How passive DNS is collected, how it exposes campaigns, and how to pivot from one domain to an entire operation. threat intelligence · 6 min read The Attack Surface You Forgot: Scanning Your Own Infrastructure Attackers scan your perimeter every day. Most organizations scan their own once a year. Here is what external recon on yourself reveals, and why continuous beats annual. soc · 7 min read From IOC to Adversary: Attribution Basics for Blue Teams How analysts get from a single indicator to a named adversary: activity clustering, infrastructure overlap, malware lineage, false flags, and why defenders should care more about how than who. threat intelligence · 6 min read Alert Fatigue Is a Design Problem, Not a Staffing Problem SOCs do not drown because they lack analysts. They drown because the alert pipeline was never designed. Here is a framework for fixing it end to end. soc · 6 min read
Every article →