Tutorials
Step-by-step guides for SOC training
10 articles

Kusto Query Language (KQL): A SOC Analyst's Practical Tutorial
Kusto Query Language (KQL) is how you query Microsoft Sentinel and Defender XDR logs. Learn to read a KQL query, write one, and run two real triage examples.

Sigma Rules Explained: A SOC Analyst's Reading Guide
Sigma rules are a vendor-agnostic YAML format for writing one SIEM detection that runs anywhere. Learn to read one, write one, and map it to MITRE ATT&CK.

How to Read Windows Event Logs: A SOC Analyst Guide
How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

MITRE ATT&CK Explained: A SOC Analyst's Field Guide
What MITRE ATT&CK actually is, how tactics and techniques work together, and how tier-1 analysts use the framework to triage alerts and find gaps.

Phishing Email Examples: 15 Analyzed by a SOC Analyst
Phishing email examples analyzed with real analyst eyes: red flags, header tells, and the patterns every security-aware person should recognize.

SIEM Use Cases: 10 Every SOC Runs (With Detection Logic)
SIEM use cases explained with detection logic sketches, data sources, and tuning notes for the 10 detections every SOC team operates.

Windows Event IDs Cheat Sheet: The 31 That Matter
Windows event IDs cheat sheet for SOC analysts: 31 essential security event IDs covering auth, process execution, log tampering, and lateral movement.

Common Ports Cheat Sheet: 42 Ports SOC Analysts Memorize
Common ports cheat sheet for SOC analysts — master the 42 TCP/UDP ports that appear in firewall logs, SIEM alerts, and security interviews every single day.

How to Analyze a Phishing Email: SOC Walkthrough
A step-by-step SOC workflow to analyze a phishing email: safe handling, header forensics, URL and attachment triage, and a documented verdict.