| 2018-04-18 | 检测攻击的基础日志服务器 Part2:日志聚合 | ourren | 2045 | |
| 2018-04-09 | Threat Hunting & Adversary Emulation: The HELK vs APTSimulator - Part 1 | ourren | 2314 | |
| 2018-04-09 | Threat Hunting & Adversary Emulation: The HELK vs APTSimulator - Part 2 | ourren | 2211 | |
| 2018-04-08 | Python工具分析风险数据 | bigsec岂安科技 | 6188 | |
| 2018-04-08 | 犯罪情报分析师知识和能力清单(初稿) | ourren | 1911 | |
| 2018-04-04 | A Study on Threat Intelligence Platforms (TIPs) | ourren | 1598 | |
| 2018-04-04 | Threat Hunting via Windows Event Logs | ourren | 1949 | |
| 2018-04-02 | Bitcoin and Cryptocurrency Tracking with the ELK Stack | ourren | 9255 | |
| 2018-03-31 | YARA Rules for Finding and Analyzing in InfoSec | ourren | 2212 | |
| 2018-03-29 | Exploring the opportunities and limitations of Threat Intelligence Platforms | ourren | 2501 | |
| 2018-03-27 | Signature Based Detection of User Events for PostMortem Forensic Analysis | tolive | 1840 | |
| 2018-03-25 | Attack Infrastructure Logging – Part 4: Log Event Alerting | ourren | 2319 | |
| 2018-03-25 | Attack Infrastructure Logging – Part 3: Graylog Dashboard 101 | ourren | 2851 | |