Blue Team
of One
SOC
IR
Identity
Endpoint
Email
Detection
Cloud
Forensics
PS
Search
⌘
K
practitioner field notes · defensive security
Real defensive work,
written honestly.
Ram Mudigina
✓ Verified
Security Lead · Surya Technologies · Bengaluru
27
Field notes
09
Verticals
100%
From real work
Windows PowerShell — BlueTeam
PS BlueTeam:\
>
Get-Vertical
|
Format-Table
-Auto
// pick a drawer
Code
Vertical
Focus
Notes
────────
──────────────────
──────────────────────────────────────────
──────
IDN
Identity Security
Tokens, Conditional Access, PIM, passwordless
9
EDR
Endpoint Security
EDR, hardening, Intune, LAPS
4
DFIR
Digital Forensics
Legal holds, eDiscovery, preservation
3
MAIL
Email Security
Mail flow, phishing, delegation
3
IR
Incident Response
Containment and honest writeups
2
DET
Detection Engineering
KQL hunting, Sentinel rules
2
CLD
Cloud Security
Secure access, posture
2
SOC
SOC Operations
Triage, workflow, automation
1
PS
PowerShell Library
Reusable blue-team scripts
1
PS BlueTeam:\
>
Get-FieldNote
-Newest
4
// latest, newest first
FN-027 · PS
A privileged-access reporter: who holds admin, and is it standing or JIT?
✓ Aug 2026
FN-026 · IDN
Temporary Access Pass is a loaded gun: using it without shooting yourself
✓ Aug 2026
FN-025 · IDN
Killing standing admin: tiered privileged access with PIM
✓ Aug 2026
FN-024 · EDR
Windows Hello for Business via Intune: the two paths, and picking the right one
✓ Aug 2026
PS>
↑↓ navigate
↵ open
esc close