Home
Softono
SOC-Analyst-WriteUp-LetsDefend.io

SOC-Analyst-WriteUp-LetsDefend.io

Open source MIT
15
Stars
3
Forks
0
Issues
0
Watchers
1 week
Last Commit

About SOC-Analyst-WriteUp-LetsDefend.io

SOC Analyst Write-Ups for LetsDefend Certification. Detailed incident analysis, investigation steps, logs review, and blue team methodology.

Platforms

Web Self-hosted

Banner

A comprehensive collection of write-ups and study materials for the LetsDefend SOC Analyst Learning Path. This repository is designed to document the learning journey, provide clear explanations for various SOC concepts, and offer solutions to practical scenarios encountered during the certification process.



πŸ“ Repository Structure

The repository is organized into structured modules, following the SOC Analyst learning path. Each module includes detailed markdown write-ups and supporting visual assets.

.
β”œβ”€β”€ SOC 
β”‚   β”œβ”€β”€ Assets                       # Visual aids and screenshots used in write-ups
β”‚   β”‚
β”‚   β”œβ”€β”€ MD Files                     # Detailed markdown write-ups for each lecture
|   |   |
β”‚   |   β”œβ”€β”€ 1) SOC Fundamentals
β”‚   |   β”œβ”€β”€ 2) Cyber Kill Chain
β”‚   |   β”œβ”€β”€ 3) MITRE ATT&CK Framework
β”‚   |   β”œβ”€β”€ 4) Introduction to Phishing
|   |   β”œβ”€β”€ 5) Detecting Web Attacks
|   |   β”œβ”€β”€ 6) Detecting Web Attacks - 2
|   |   β”œβ”€β”€ 7) How to Investigate a SIEM Alert 
|   |   β”œβ”€β”€ 8) Malware Analysis Fundamentals
|   |   β”œβ”€β”€ 9) Dynamic Malware Analysis
|   |   β”œβ”€β”€ 10) Malicious Document Analysis
|   |   β”œβ”€β”€ 11) Security Solutions
|   |   β”œβ”€β”€ 12) Network Log Analysis
|   |   β”œβ”€β”€ 13) SIEM 101
|   |   β”œβ”€β”€ 14) Incident Management 101 
|   |   β”œβ”€β”€ 15) Splunk
|   |   β”œβ”€β”€ 16) Cyber Threat Intelligence
|   |   β”œβ”€β”€ 17) VirusTotal for SOC Analysts
|   |   β”œβ”€β”€ 18) IT Security Basis for Corporates
|   |   β”œβ”€β”€ 19) Detecting Brute Force Attacks
|   |   └── 20) Building a Malware Analysis Lab
|   |
|   └── Labs
|       |    
|       β”œβ”€β”€ 1) SOC282 - Phishing Alert
|       β”œβ”€β”€ 2) 28 - SOC105 - Requested T.I. URL address
|       β”œβ”€β”€ 3) 36 - SOC104 - Malware Detected
|       β”œβ”€β”€ 4) 83 - SOC119 - Proxy - Malicious Executable File Detected
|       β”œβ”€β”€ 5) 85 - SOC109 - Proxy - Emotet Malware Detected
|       β”œβ”€β”€ 6) 84 - SOC104 - Malware Detected
|       β”œβ”€β”€ 7) 92 - SOC145 - Ransomware Detected
|       β”œβ”€β”€ 8) 20 - SOC105 - Requested T.I. URL address
|       β”œβ”€β”€ 9) 14 - SOC104 - Malware Detected
|       β”œβ”€β”€ 10) 75 - SOC105 - Requested T.I. URL address
|       β”œβ”€β”€ 11) 76 - SOC137 - Malicious File Script Download Attempt
|       └── 12) 320 - SOC342 - CVE‑2025‑53770 SharePoint ToolShell Auth Bypass and RCE
|
|
β”œβ”€β”€ LICENSE                          # MIT License
└── README.md                        # Project overview and structure

alt text

πŸ“š Modules Covered

πŸ–₯️ Labs Covered

πŸŽ“ Certificate

LetsDefend SOC Analyst Certificate

πŸ“œ License

This project is licensed under the MIT License - see the LICENSE file for details.


Disclaimer: These write-ups are for educational purposes and are based on the LetsDefend SOC Analyst Learning Path.