These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC.
These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a more structured timeline approach and incorporate advice from working SMEs and practitioners.
For Let’sDefend notes, there will be tags for T1/T2 or for Security Analyst/Incident Responder. These tags indicate which cases I handle with basic triage (T1) or with deep-dive, comprehensive investigations (T2).
SOC Investigation: Phishing → Malware Execution
Tags: Lazarus Phishing Campaign Detected (APT38), Incident Responder/T2
Investigation Date: 7/31/2026
SOC Investigation: SSH Brute Force → Credential Enumeration & Data Exposure
Tags: Suspicious Base64 Encoding/Decoding Commands Detected, Incident Responder/T2
Investigation Date: 2/11/2026
SOC Investigation: Malicious PDF → Payload Execution
Tags: Possible MalDoc in PDF was Detected, Incident Responder/T2
Investigation Date: 12/4/2024
SOC Investigation: Brute-Force Access → Mimikatz Execution
Tags: Unauthorized Access – Hack Tool Executed, Incident Responder/T2
Investigation Date: 11/5/2024
SOC Investigation: NTDS Credential Dumping & Exfiltration
Tags: Unauthorized Access to NTDS.dit File Detected, Incident Responder/T2
Investigation Date: 9/6/2024
SOC Investigation: Cobalt Strike C2 & Living-off-the-Land Activity
Tags: Meterpreter or Empire activity detected, Security Analyst/T1
Investigation Date: 8/29/2024
SOC Investigation: SQL Injection → Command Injection → Reverse Shell
Tags: Multiple 500 Resp Codes, Security Analyst/T1
Investigation Date: 8/23/2024
SOC Investigation:
Tags:
Investigation Date:
SOC Investigation:
Tags:
Investigation Date:
