🔒 Complete Guide for SOC Tier 1 Analysts!
This comprehensive cheat sheet contains all the essential information SOC
Tier 1 analysts need to excel at their daily responsibilities in Security
Operations Centers.
📋 What's Inside?
✅ TRIAGE PROCESS
• Distinguish between True Positive and False Positive (in seconds)
• Context analysis: IP ownership, system criticality, user privileges
• 15-minute log scanning and hash analysis
• Close, Quarantine, or escalate to Tier 2 decisions
✅ CRITICAL EVENT IDs (4624, 4625, 4688, 4720, 1102)
• Successful Logon events (4624)
• Failed Logon attempts - Brute Force indicators (4625)
• New Process Started - Unknown .exe detection (4688)
• New User Created - Persistence indicators (4720)
• Log Clearing - Attacker trace removal (1102)
✅ CRITICAL PORTS (SSH, RDP, DNS, SMB, HTTP/HTTPS)
• Ports that should never be exposed to the outside world
• Ransomware entry points
• Data Exfiltration methods
• Lateral Movement routes
• C2 (Command & Control) tunnels
✅ ANALYSIS CHECKLIST
• IP/Domain reputation checks (VirusTotal, AbuseIPDB)
• Malware family identification
• Chronological Timeline creation
• Lateral spread analysis
• Base64 and Obfuscated code detection
✅ TIER 2 ESCALATION CRITERIA
• Ransomware encryption (Immediate Escalation)
• Privilege Escalation detection
• Gigabyte-scale data exfiltration
• Suspicious processes on Domain Controller
🎯 Who Is This For?
→ SOC Tier 1 analysts
→ Beginner-level cybersecurity professionals
→ SIEM and security event analysis practitioners
→ Threat detection and incident response learners
📱 Format: PDF + Markdown versions
⚡ Quick Reference: Every section is concise and practical
🔄 Updated: Covers latest threats