
A comprehensive collection of write-ups and study materials for the LetsDefend SOC Analyst Learning Path. This repository is designed to document the learning journey, provide clear explanations for various SOC concepts, and offer solutions to practical scenarios encountered during the certification process.
π Repository Structure
The repository is organized into structured modules, following the SOC Analyst learning path. Each module includes detailed markdown write-ups and supporting visual assets.
.
βββ SOC
β βββ Assets # Visual aids and screenshots used in write-ups
β β
β βββ MD Files # Detailed markdown write-ups for each lecture
| | |
β | βββ 1) SOC Fundamentals
β | βββ 2) Cyber Kill Chain
β | βββ 3) MITRE ATT&CK Framework
β | βββ 4) Introduction to Phishing
| | βββ 5) Detecting Web Attacks
| | βββ 6) Detecting Web Attacks - 2
| | βββ 7) How to Investigate a SIEM Alert
| | βββ 8) Malware Analysis Fundamentals
| | βββ 9) Dynamic Malware Analysis
| | βββ 10) Malicious Document Analysis
| | βββ 11) Security Solutions
| | βββ 12) Network Log Analysis
| | βββ 13) SIEM 101
| | βββ 14) Incident Management 101
| | βββ 15) Splunk
| | βββ 16) Cyber Threat Intelligence
| | βββ 17) VirusTotal for SOC Analysts
| | βββ 18) IT Security Basis for Corporates
| | βββ 19) Detecting Brute Force Attacks
| | βββ 20) Building a Malware Analysis Lab
| |
| βββ Labs
| |
| βββ 1) SOC282 - Phishing Alert
| βββ 2) 28 - SOC105 - Requested T.I. URL address
| βββ 3) 36 - SOC104 - Malware Detected
| βββ 4) 83 - SOC119 - Proxy - Malicious Executable File Detected
| βββ 5) 85 - SOC109 - Proxy - Emotet Malware Detected
| βββ 6) 84 - SOC104 - Malware Detected
| βββ 7) 92 - SOC145 - Ransomware Detected
| βββ 8) 20 - SOC105 - Requested T.I. URL address
| βββ 9) 14 - SOC104 - Malware Detected
| βββ 10) 75 - SOC105 - Requested T.I. URL address
| βββ 11) 76 - SOC137 - Malicious File Script Download Attempt
| βββ 12) 320 - SOC342 - CVEβ2025β53770 SharePoint ToolShell Auth Bypass and RCE
|
|
βββ LICENSE # MIT License
βββ README.md # Project overview and structure

π Modules Covered
- SOC Fundamentals
- Cyber Kill Chain
- MITRE ATT&CK Framework
- Introduction to Phishing
- Detecting Web Attacks
- Detecting Web Attacks - 2
- How to Investigate a SIEM Alert
- Malware Analysis Fundamentals
- Dynamic Malware Analysis
- Malicious Document Analysis
- Security Solutions
- Network Log Analysis
- SIEM 101
- Incident Management 101
- Splunk
- Cyber Threat Intelligence
- VirusTotal for SOC Analysts
- IT Security Basis for Corporates
- Detecting Brute Force Attacks
- Building a Malware Analysis Lab
π₯οΈ Labs Covered
- 75 - SOC105 - Requested T.I. URL address
- 14 - SOC104 - Malware Detected
- 36 - SOC104 - Malware Detected
- 83 - SOC119 - Proxy - Malicious Executable File Detected
- 85 - SOC109 - Proxy - Emotet Malware Detected
- 84 - SOC104 - Malware Detected
- 92 - SOC145 - Ransomware Detected
- 20 - SOC105 - Requested T.I. URL address
- 28 - SOC105 - Requested T.I. URL address
- 76 - SOC137 - Malicious File Script Download Attempt
- 320 - SOC342 - CVE-2025-53770 SharePoint ToolShell Auth Bypass and RCE
π Certificate
π License
This project is licensed under the MIT License - see the LICENSE file for details.
Disclaimer: These write-ups are for educational purposes and are based on the LetsDefend SOC Analyst Learning Path.