SOC Investigation Note Samples


These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC.

These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a more structured timeline approach and incorporate advice from working SMEs and practitioners.

For Let’sDefend notes, there will be tags for T1/T2 or for Security Analyst/Incident Responder. These tags indicate which cases I handle with basic triage (T1) or with deep-dive, comprehensive investigations (T2).

SOC Investigation: Phishing → Malware Execution

Tags: Lazarus Phishing Campaign Detected (APT38), Incident Responder/T2

Investigation Date: 7/31/2026

SOC Investigation: SSH Brute Force → Credential Enumeration & Data Exposure

Tags: Suspicious Base64 Encoding/Decoding Commands Detected, Incident Responder/T2

Investigation Date: 2/11/2026

SOC Investigation: Malicious PDF → Payload Execution

Tags: Possible MalDoc in PDF was Detected, Incident Responder/T2

Investigation Date: 12/4/2024

SOC Investigation: Brute-Force Access → Mimikatz Execution

Tags: Unauthorized Access – Hack Tool Executed, Incident Responder/T2

Investigation Date: 11/5/2024

SOC Investigation: NTDS Credential Dumping & Exfiltration

Tags: Unauthorized Access to NTDS.dit File Detected, Incident Responder/T2

Investigation Date: 9/6/2024

SOC Investigation: Cobalt Strike C2 & Living-off-the-Land Activity

Tags: Meterpreter or Empire activity detected, Security Analyst/T1

Investigation Date: 8/29/2024

SOC Investigation: SQL Injection → Command Injection → Reverse Shell

Tags: Multiple 500 Resp Codes, Security Analyst/T1

Investigation Date: 8/23/2024

SOC Investigation:

Tags:

Investigation Date:

SOC Investigation:

Tags:

Investigation Date: