Skip to main content
AL

Author

Astrid Lindqvist

Content Strategist, SOCSimulator

Astrid is the Content Strategist at SOCSimulator, where she shapes the detection scenarios, attack narratives, and learning paths analysts train against. She comes from a blue-team background, with years spent close to live SOC operations, triaging alerts and tuning detections, and now turns that reality into structured, hands-on training. She writes about the craft of detection and response, and the human side of working a SOC shift.

Articles by Astrid Lindqvist

Abstract dark chart of web request volume where one isolated bar is highlighted and branches into a small process tree
Tutorials

Web Shell Detection: KQL, IIS Logs and a 30-Minute Triage

The process-parent rule that finds web shells, the false positive that gets it muted, IIS log tells in KQL and Splunk, and an ordered first 30 minutes.

Abstract dark illustration of numbered authentication paths converging on a single Windows security log entry
Tutorials

Windows Logon Types: A Triage Guide for Every 4624 Value

Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Abstract dark illustration of a glowing authentication code fracturing into token shards drifting toward a shadowed terminal
Tutorials

Device Code Phishing: How OAuth Token Theft Bypasses MFA (and How to Detect It)

Device code phishing steals OAuth tokens after the victim passes MFA. Learn how the attack works and the Entra log signals that expose it.

Abstract dark illustration of a shattered screen with glowing amber binary code bursting through it
Tutorials

Redline Stealer Analysis: How Infostealers Work and How to Detect Them

Redline Stealer is a malware-as-a-service infostealer that steals credentials, tokens, clipboard data, and screenshots. Learn to detect and triage it.

Abstract layered rows of translucent amber panels flowing left to right against a dark background, suggesting data moving through sequential stages
Tutorials

Kusto Query Language (KQL): A SOC Analyst's Practical Tutorial

Kusto Query Language (KQL) is how you query Microsoft Sentinel and Defender XDR logs. Learn to read a KQL query, write one, and run two real triage examples.

Abstract rows of dark ridged slats curving across a black background, lit by a warm orange glow, evoking parallel paths fanning out from one source
Tutorials

Sigma Rules Explained: Read, Write, and Convert One

Sigma rules are vendor-agnostic YAML detections. Read one rule field by field, then see its real sigma-cli output in Splunk SPL and Microsoft Sentinel KQL.

Abstract rows of dark glass slats receding diagonally with a warm orange glow, evoking scrolling log lines
Tutorials

How to Read Windows Event Logs: A SOC Analyst Guide

How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

Abstract dark grid of glass panels receding into shadow, lit by a warm orange glow, evoking the MITRE ATT&CK matrix
Tutorials

MITRE ATT&CK for SOC Analysts: Tactics, IDs, Examples

All 15 Enterprise tactic IDs (Lateral Movement is TA0008), how techniques nest under them, and a worked alert chain mapped to ATT&CK step by step.

Person at a MacBook Pro with a messaging app open in a cafe, simultaneously scrolling on a smartphone, iced drink on the table
Tutorials

Phishing Email Examples: 15 Analyzed by a SOC Analyst

Phishing email examples analyzed with real analyst eyes: red flags, header tells, and the patterns every security-aware person should recognize.

Dual-monitor workstation in a dark room showing code on an iMac and a landscape wallpaper on a second display, lit by a desk lamp
Best Practices

Best EDR Tools in 2026: What Tier 1 Analysts Learn First

Best EDR tools for SOC analysts: CrowdStrike, Defender, SentinelOne, Cortex XDR and more, ranked by console learnability and job-market frequency.

Green Matrix-style falling code characters cascading down a pure black background, representing data stream analysis and threat hunting
Best Practices

Cyber Threat Hunting Tools: 13 SOC Analysts Use (2026)

Cyber threat hunting tools every SOC analyst needs: Sigma, YARA, KQL, Velociraptor, Wireshark, Zeek, MISP and more, grouped by layer with code examples.

Silhouetted figures standing inside a dark immersive installation with cascading blue-white data lights falling like rain around them
Tutorials

SIEM Use Cases: 10 Every SOC Runs (With Detection Logic)

SIEM use cases explained with detection logic sketches, data sources, and tuning notes for the 10 detections every SOC team operates.

Dark analytics dashboard on a tablet screen displaying colorful performance charts and session metrics against a black background
Best Practices

Best SIEM Tools in 2026: 12 Platforms Ranked

12 best SIEM tools for 2026, re-checked in September: Splunk under Cisco, QRadar SaaS moved to Cortex XSIAM, pricing models, and who each one fits.

MacBook Pro on a dark desk with a colorful code editor open showing syntax-highlighted source code in a dark theme
Best Practices

Open Source SIEM: 7 Free Tools for Your Home Lab (2026)

Open source SIEM tools to self-host on Linux with Docker: Wazuh, OpenSearch and 5 more, with RAM specs and which licenses are truly open source.

Hand holding a blue pen writing notes on paper at a wooden desk with a coffee mug and notebook beside it
Best Practices

Best Cybersecurity Certifications for Beginners: 2026 Costs

8 beginner certs ranked for SOC analyst jobs, with prices checked on each issuer's site in Sept 2026: Security+ $439, BTL1 £399, ISC2 CC no longer free.

Windows Security event log entries displayed in a SIEM console, showing event IDs for authentication and process activity
Tutorials

Windows Event IDs & Codes Cheat Sheet: The 31 That Matter

The 31 Windows event IDs and codes SOC analysts triage most: logon, Kerberos, process, services, Sysmon, log clearing, plus detection pages for 12 of them.

Network traffic analysis dashboard showing TCP and UDP port connections, firewall logs, and protocol distribution for SOC triage
Tutorials

Common Port Numbers Cheat Sheet: 42 Ports for SOC Triage

The 42 TCP/UDP port numbers SOC analysts read in firewall logs and SIEM alerts, what each one means in triage, and a printable cheat sheet image to save.

Wax-sealed envelope beside a magnifying glass on a dark surface with a glowing phishing hook and orange code overlay in the background
Tutorials

How to Analyze a Phishing Email: SOC Walkthrough

A step-by-step SOC workflow to analyze a phishing email: safe handling, header forensics, URL and attachment triage, and a documented verdict.

Close-up of a dark SIEM dashboard on a widescreen monitor, rows of alerts highlighted in orange, gloved hands at the keyboard
Tutorials

Alert Triage: Real Threats vs False Positives

Alert triage is the core SOC skill. Learn the framework analysts use to assess severity, confirm IOCs, and separate real threats from false positives.

Two silhouettes facing each other across a table with a large curved orange-lit world map and data dashboard screen behind them
Best Practices

SOC Analyst Interview Questions: 30 With Answers

SOC analyst interview questions decoded: what interviewers test, sample answers, and log examples to study before your first security ops interview.

Tiered salary bands for SOC analyst roles from Tier 1 entry-level to Tier 3 senior, displayed as a compensation ladder in a security context
Best Practices

SOC Analyst Salary 2026: Tier 1 to Tier 3 ($48K to $145K)

Tier 1 SOC analysts earn $48,000 to $72,000; Tier 3 and leads reach $145,000. Honest ranges by tier, location, and cert, from BLS and aggregator data.

3D orange glowing staircase path curving across a dark circuit-board landscape toward an illuminated SOC building on the horizon
Best Practices

How to Become a SOC Analyst (With or Without a Degree)

How to become a SOC analyst: a realistic roadmap from IT helpdesk to SOC, covering certs, hands-on practice, and what hiring managers actually screen for.

Dimly lit security operations center with a lone analyst seated at a curved desk of orange-glowing monitors, server racks lining the walls
Best Practices

What Does a SOC Analyst Do? The Role, Explained by Tier

What does a SOC analyst do? A tier-by-tier breakdown of the role, a realistic daily shift, tools, skills, and common myths, for career switchers.