SOC field reference

DeepBlueCLI Field Guide

Eric Conrad's PowerShell triage script for the Windows Event Log — the fast first pass before you've even opened a SIEM, run straight against an exported .evtx or a live log. Organized by how to run it, what it's built to catch, and exactly how to read what it prints.

Click any card for why it matters, what a suspicious value looks like, its IOC type, and exactly how to pull it up.

Usage & Parameters

PowerShell Script

A PowerShell script, not a GUI tool — run it directly against exported .evtx files or a live Windows Event Log, tuned with a handful of flags.

.\DeepBlue.ps1 -log security

Detections & Findings

Built-in Modules

What DeepBlueCLI is actually built to catch — each of these is a built-in detection, not something you configure yourself.

Detection: Regex match — Encoded command

No fields match that filter.