Tutorials
Step-by-step tutorials for SOC analysts: log analysis, KQL and Sigma, SIEM and XDR investigation, and hands-on alert triage you can practice on SOCSimulator.

Phishing Email Examples: 15 Analyzed by a SOC Analyst
Phishing email examples analyzed with real analyst eyes: red flags, header tells, and the patterns every security-aware person should recognize.

SIEM Use Cases: 10 Every SOC Runs (With Detection Logic)
SIEM use cases explained with detection logic sketches, data sources, and tuning notes for the 10 detections every SOC team operates.

Windows Event IDs & Codes Cheat Sheet: The 31 That Matter
The 31 Windows event IDs and codes SOC analysts triage most: logon, Kerberos, process, services, Sysmon, log clearing, plus detection pages for 12 of them.

Common Port Numbers Cheat Sheet: 42 Ports for SOC Triage
The 42 TCP/UDP port numbers SOC analysts read in firewall logs and SIEM alerts, what each one means in triage, and a printable cheat sheet image to save.

How to Analyze a Phishing Email: SOC Walkthrough
A step-by-step SOC workflow to analyze a phishing email: safe handling, header forensics, URL and attachment triage, and a documented verdict.

Alert Triage: Real Threats vs False Positives
Alert triage is the core SOC skill. Learn the framework analysts use to assess severity, confirm IOCs, and separate real threats from false positives.