SOC Investigation Note Samples


These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC.

These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a more structured timeline approach and incorporate advice from working SMEs and practitioners.

For Let’sDefend notes, there will be tags for T1/T2 or for Security Analyst/Incident Responder. These tags indicate which cases I handle with basic triage (T1) or with deep-dive, comprehensive investigations (T2).

LetsDefend Event ID 278

Tags: Suspicious Base64 Encoding/Decoding Commands Detected, Incident Responder/T2

Investigation Date: 2/11/2026