π Complete Guide for SOC Tier 1 Analysts!
This comprehensive cheat sheet contains all the essential information SOC
Tier 1 analysts need to excel at their daily responsibilities in Security
Operations Centers.
π What's Inside?
β
TRIAGE PROCESS
β’ Distinguish between True Positive and False Positive (in seconds)
β’ Context analysis: IP ownership, system criticality, user privileges
β’ 15-minute log scanning and hash analysis
β’ Close, Quarantine, or escalate to Tier 2 decisions
β
CRITICAL EVENT IDs (4624, 4625, 4688, 4720, 1102)
β’ Successful Logon events (4624)
β’ Failed Logon attempts - Brute Force indicators (4625)
β’ New Process Started - Unknown .exe detection (4688)
β’ New User Created - Persistence indicators (4720)
β’ Log Clearing - Attacker trace removal (1102)
β
CRITICAL PORTS (SSH, RDP, DNS, SMB, HTTP/HTTPS)
β’ Ports that should never be exposed to the outside world
β’ Ransomware entry points
β’ Data Exfiltration methods
β’ Lateral Movement routes
β’ C2 (Command & Control) tunnels
β
ANALYSIS CHECKLIST
β’ IP/Domain reputation checks (VirusTotal, AbuseIPDB)
β’ Malware family identification
β’ Chronological Timeline creation
β’ Lateral spread analysis
β’ Base64 and Obfuscated code detection
β
TIER 2 ESCALATION CRITERIA
β’ Ransomware encryption (Immediate Escalation)
β’ Privilege Escalation detection
β’ Gigabyte-scale data exfiltration
β’ Suspicious processes on Domain Controller
π― Who Is This For?
β SOC Tier 1 analysts
β Beginner-level cybersecurity professionals
β SIEM and security event analysis practitioners
β Threat detection and incident response learners
π± Format: PDF + Markdown versions
β‘ Quick Reference: Every section is concise and practical
π Updated: Covers latest threats