Big Billion davidogun100@gmail.com 10:42 PM (0 minutes ago) to savenet419
Documenting my journey to becoming a Tier 1 SOC Analyst through hands-on labs, alert triage, and detection engineering.
Aspiring SOC Analyst currently training with Let'sDefend SOC Simulator. Focus: SIEM, Incident Response, Threat Detection, MITRE ATT&CK
| Alert ID | Type | Verdict | MITRE ATT&CK |
|---|---|---|---|
| SOC282 | Phishing Email | True Positive | T1566.001 |
| SOC153 | Suspicious Powershell | True Positive | T1059.001 |
| SOC127 | SQL Injection | True Positive | T1190 |
All case studies and screenshots are in 01-SIEM-Alerts/
- Splunk Free - SIEM
- Wazuh - EDR/SIEM
- Sysmon - Windows Logging
- Atomic Red Team - Attack Simulation
Complete 7-day SOC Bootcamp and document 15+ alerts with full IR workflow.
LinkedIn:
- Built Splunk Playbook with 3 triage queries for SOC Analyst role
Scenario
An attacker attempted to brute force user accounts by sending multiple failed login requests from a single IP address.
Alert Details
- Severity: High
- Source: Web Server Logs
- Indicator: 127 failed login attempts from
192.168.1.10
Detection
- Tool Used: Splunk Enterprise
- SPL Query:
brute-force-splunk.spl
Investigation & Findings Ran SPL query to count failed 401s by source IP. Result:
Result: 192.168.1.10 had 4 failed login attempts within 5 seconds. This exceeded our threshold of 3 attempts.
Evidence
Figure 1: Splunk statistics showing 4 failed attempts from attacker IP
Containment & Response
- Blocked IP
192.168.1.10at firewall - Forced password reset for targeted accounts
- Created alert rule for future brute force attempts
- Notified SOC Lead
MITRE ATT&CK: T1110.001 - Brute Force: Password Guessing
Scenario
An endpoint executed a suspicious PowerShell command with encoded parameters, likely used to download and execute malware without touching disk.
Alert Details
- Severity: Critical
- Source: Windows Event Logs 4104 + Sysmon
- Indicator:
powershell.exe -encodedcommand JABzAD...
Detection
- Tool Used: Splunk Enterprise + Sysmon
- SPL Query:
suspicious-powershell.spl
Investigation & Findings
Searched for ProcessName=powershell with encoded flags. Result:
WKSTN-042 User jdoe executed encoded PowerShell that called Invoke-WebRequest to http://malicious.com/payload.exe.
Evidence Screenshot: Splunk detection showing 1 event - Computer: WKSTN-042, User: jdoe, Flags: -encodedcommand, CommandLine: powershell.exe -e JABzAD0ATgBl... Image pending upload
Containment & Response
- Killed malicious
powershell.exeprocess onWKSTN-042 - Isolated host from network via EDR
- Blocked C2 domain
malicious.comat firewall - Searched for persistence in Task Scheduler and Registry Run keys
MITRE ATT&CK: T1059.001 - Command and Scripting Interpreter: PowerShell
By Davidking100
Hands-on SOC analyst portfolio with 5 incident response case studies.
- Case 01: Brute Force Attack - SIEM Alert Thresholds
- Case 02: Suspicious DNS Tunneling - Network Anomalies
- Case 03: DNS Traffic Baseline - Threat Hunting
- Case 04: Suspicious PowerShell - LOLBAS + EventID 4104 + MITRE
- Case 05: Phishing Email Triage - IOC Extraction + MITRE
- Case 06: Malware Alert Investigation - EDR + Process Analysis
Splunk/SIEM, Wireshark, VirusTotal, Microsoft Defender, MITRE ATT&CK
Demonstrate practical blue team skills for SOC Analyst Level 1 roles.