Author
Astrid Lindqvist
Content Strategist, SOCSimulator
Astrid is the Content Strategist at SOCSimulator, where she shapes the detection scenarios, attack narratives, and learning paths analysts train against. She comes from a blue-team background, with years spent close to live SOC operations, triaging alerts and tuning detections, and now turns that reality into structured, hands-on training. She writes about the craft of detection and response, and the human side of working a SOC shift.
Articles by Astrid Lindqvist

Web Shell Detection: KQL, IIS Logs and a 30-Minute Triage
The process-parent rule that finds web shells, the false positive that gets it muted, IIS log tells in KQL and Splunk, and an ordered first 30 minutes.

Windows Logon Types: A Triage Guide for Every 4624 Value
Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Device Code Phishing: How OAuth Token Theft Bypasses MFA (and How to Detect It)
Device code phishing steals OAuth tokens after the victim passes MFA. Learn how the attack works and the Entra log signals that expose it.

Redline Stealer Analysis: How Infostealers Work and How to Detect Them
Redline Stealer is a malware-as-a-service infostealer that steals credentials, tokens, clipboard data, and screenshots. Learn to detect and triage it.

Kusto Query Language (KQL): A SOC Analyst's Practical Tutorial
Kusto Query Language (KQL) is how you query Microsoft Sentinel and Defender XDR logs. Learn to read a KQL query, write one, and run two real triage examples.

Sigma Rules Explained: Read, Write, and Convert One
Sigma rules are vendor-agnostic YAML detections. Read one rule field by field, then see its real sigma-cli output in Splunk SPL and Microsoft Sentinel KQL.

How to Read Windows Event Logs: A SOC Analyst Guide
How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

MITRE ATT&CK for SOC Analysts: Tactics, IDs, Examples
All 15 Enterprise tactic IDs (Lateral Movement is TA0008), how techniques nest under them, and a worked alert chain mapped to ATT&CK step by step.

Phishing Email Examples: 15 Analyzed by a SOC Analyst
Phishing email examples analyzed with real analyst eyes: red flags, header tells, and the patterns every security-aware person should recognize.

Best EDR Tools in 2026: What Tier 1 Analysts Learn First
Best EDR tools for SOC analysts: CrowdStrike, Defender, SentinelOne, Cortex XDR and more, ranked by console learnability and job-market frequency.

Cyber Threat Hunting Tools: 13 SOC Analysts Use (2026)
Cyber threat hunting tools every SOC analyst needs: Sigma, YARA, KQL, Velociraptor, Wireshark, Zeek, MISP and more, grouped by layer with code examples.

SIEM Use Cases: 10 Every SOC Runs (With Detection Logic)
SIEM use cases explained with detection logic sketches, data sources, and tuning notes for the 10 detections every SOC team operates.

Best SIEM Tools in 2026: 12 Platforms Ranked
12 best SIEM tools for 2026, re-checked in September: Splunk under Cisco, QRadar SaaS moved to Cortex XSIAM, pricing models, and who each one fits.

Open Source SIEM: 7 Free Tools for Your Home Lab (2026)
Open source SIEM tools to self-host on Linux with Docker: Wazuh, OpenSearch and 5 more, with RAM specs and which licenses are truly open source.

Best Cybersecurity Certifications for Beginners: 2026 Costs
8 beginner certs ranked for SOC analyst jobs, with prices checked on each issuer's site in Sept 2026: Security+ $439, BTL1 £399, ISC2 CC no longer free.

Windows Event IDs & Codes Cheat Sheet: The 31 That Matter
The 31 Windows event IDs and codes SOC analysts triage most: logon, Kerberos, process, services, Sysmon, log clearing, plus detection pages for 12 of them.

Common Port Numbers Cheat Sheet: 42 Ports for SOC Triage
The 42 TCP/UDP port numbers SOC analysts read in firewall logs and SIEM alerts, what each one means in triage, and a printable cheat sheet image to save.

How to Analyze a Phishing Email: SOC Walkthrough
A step-by-step SOC workflow to analyze a phishing email: safe handling, header forensics, URL and attachment triage, and a documented verdict.

Alert Triage: Real Threats vs False Positives
Alert triage is the core SOC skill. Learn the framework analysts use to assess severity, confirm IOCs, and separate real threats from false positives.

SOC Analyst Interview Questions: 30 With Answers
SOC analyst interview questions decoded: what interviewers test, sample answers, and log examples to study before your first security ops interview.

SOC Analyst Salary 2026: Tier 1 to Tier 3 ($48K to $145K)
Tier 1 SOC analysts earn $48,000 to $72,000; Tier 3 and leads reach $145,000. Honest ranges by tier, location, and cert, from BLS and aggregator data.

How to Become a SOC Analyst (With or Without a Degree)
How to become a SOC analyst: a realistic roadmap from IT helpdesk to SOC, covering certs, hands-on practice, and what hiring managers actually screen for.

What Does a SOC Analyst Do? The Role, Explained by Tier
What does a SOC analyst do? A tier-by-tier breakdown of the role, a realistic daily shift, tools, skills, and common myths, for career switchers.