SOC field reference
Eric Conrad's PowerShell triage script for the Windows Event Log — the fast first pass before
you've even opened a SIEM, run straight against an exported .evtx or a live log.
Organized by how to run it, what it's built to catch, and exactly how to read what it prints.
Click any card for why it matters, what a suspicious value looks like, its IOC type, and exactly how to pull it up.
A PowerShell script, not a GUI tool — run it directly against exported .evtx files or a live Windows Event Log, tuned with a handful of flags.
.\DeepBlue.ps1 -log security
What DeepBlueCLI is actually built to catch — each of these is a built-in detection, not something you configure yourself.
Detection: Regex match — Encoded command
No fields match that filter.