SOC alert triage and incident investigation exercises completed using LetsDefend labs.
- Alert Triage
- SIEM Investigation
- Windows Event Analysis
- Endpoint Investigation
- IOC Identification
- Threat Analysis
| Investigation | Focus |
|---|---|
| Sigma Rule Challenge | Detection Logic Practice |
| Ransomware Command-Line Analysis | Threat Investigation |
| Windows Process Investigation | Endpoint Analysis |
- Alert Validation
- IOC Investigation
- MITRE ATT&CK Mapping
- Windows Event Investigation
- Basic Detection Logic Analysis
- LetsDefend SIEM
- Sysmon
- Windows Event Logs
- Sigma Rules
- MITRE ATT&CK