Skip to main content
Back to all posts

Tutorials

Step-by-step tutorials for SOC analysts: log analysis, KQL and Sigma, SIEM and XDR investigation, and hands-on alert triage you can practice on SOCSimulator.

Abstract dark data visualisation of two authentication paths running side by side, one traced in amber, converging on a single log entry
Tutorials

NTLM vs Kerberos: Differences and How to Read Them in Logs

NTLM vs Kerberos side by side, the 4624, 4776 and 4769 fields that show which one ran, why Windows falls back, and SPL and KQL that catch a downgrade.

Abstract dark chart of web request volume where one isolated bar is highlighted and branches into a small process tree
Tutorials

Web Shell Detection: KQL, IIS Logs and a 30-Minute Triage

The process-parent rule that finds web shells, the false positive that gets it muted, IIS log tells in KQL and Splunk, and an ordered first 30 minutes.

Abstract dark illustration of numbered authentication paths converging on a single Windows security log entry
Tutorials

Windows Logon Types: A Triage Guide for Every 4624 Value

Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Abstract dark illustration of a glowing authentication code fracturing into token shards drifting toward a shadowed terminal
Tutorials

Device Code Phishing: How OAuth Token Theft Bypasses MFA (and How to Detect It)

Device code phishing steals OAuth tokens after the victim passes MFA. Learn how the attack works and the Entra log signals that expose it.

Abstract dark illustration of a shattered screen with glowing amber binary code bursting through it
Tutorials

Redline Stealer Analysis: How Infostealers Work and How to Detect Them

Redline Stealer is a malware-as-a-service infostealer that steals credentials, tokens, clipboard data, and screenshots. Learn to detect and triage it.

Abstract layered rows of translucent amber panels flowing left to right against a dark background, suggesting data moving through sequential stages
Tutorials

Kusto Query Language (KQL): A SOC Analyst's Practical Tutorial

Kusto Query Language (KQL) is how you query Microsoft Sentinel and Defender XDR logs. Learn to read a KQL query, write one, and run two real triage examples.

Abstract rows of dark ridged slats curving across a black background, lit by a warm orange glow, evoking parallel paths fanning out from one source
Tutorials

Sigma Rules Explained: Read, Write, and Convert One

Sigma rules are vendor-agnostic YAML detections. Read one rule field by field, then see its real sigma-cli output in Splunk SPL and Microsoft Sentinel KQL.

Abstract rows of dark glass slats receding diagonally with a warm orange glow, evoking scrolling log lines
Tutorials

How to Read Windows Event Logs: A SOC Analyst Guide

How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

Abstract dark grid of glass panels receding into shadow, lit by a warm orange glow, evoking the MITRE ATT&CK matrix
Tutorials

MITRE ATT&CK for SOC Analysts: Tactics, IDs, Examples

All 15 Enterprise tactic IDs (Lateral Movement is TA0008), how techniques nest under them, and a worked alert chain mapped to ATT&CK step by step.