GUIDES · ALL
How-to, end-to-end.
Battle-tested walkthroughs from the team running threatDefendr in production. Each guide is opinionated, dated, and revisited when the underlying surface changes.
ALL
DETECT
RESPOND
DEPLOY
OPERATE
SECURE
SECTORS
Detect
Authoring, testing, and operating detections.
Respond
SOAR playbooks, war rooms, and containment patterns.
Deploy
BYOC, SaaS, self-hosted — pick the perimeter, follow the recipe.
Operate
Day-2 ops, capacity, custom enrichments, and incident retrospectives.
Secure
Hardening the integration surface — webhooks, tokens, secrets.
Sector playbooks
Patterns the field team sees over and over in a given vertical.