A collection of SOC alert investigations and cybersecurity lab writeups.
| Alert | Severity | Verdict | WriteUp |
|---|---|---|---|
| SOC114 - Malicious Attachment Detected - Phishing Alert | High | True Positive | Medium |
| SOC127 - SQL Injection Detected - Web Attack Alert | High | True Positive | Medium |
| SOC336 - Windows OLE Zero-Click - Malware | Critical | True Positive | Medium |
| SOC338 - Lumma Stealer - DLL Side-Loading via Click Fix Phishing | Critical | True Positive | Medium |
| SOC335 — CVE-2024–49138 Exploitation Detected | Medium | True Positive | Medium |
| Room | Difficulty | Category | WriteUp |
|---|---|---|---|
| LockDown | Medium | AI Security (Blue Team) | Medium |
| Carnage | Medium | Network Traffic Analysis | Medium |
| Benign | Medium | Splunk Investigations | Medium |
| PS Eclipse | Medium | Splunk Ransomware Investigation | Medium |
| Investigating with Splunk | Medium | Splunk Investigations | Medium |
| TShark Challenge I: Teamwork | Easy | Network Traffic Analysis | Medium |
Written by Tamerlan Shabanov GitHub: VelvetB1te