SOC Investigation Note Samples


These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC.

These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a more structured timeline approach and incorporate advice from working SMEs and practitioners.

For Let’sDefend notes, there will be tags for T1/T2 or for Security Analyst/Incident Responder. These tags indicate which cases I handle with basic triage (T1) or with deep-dive, comprehensive investigations (T2).

LetsDefend Event ID 278

Tags: Suspicious Base64 Encoding/Decoding Commands Detected, Incident Responder/T2

Investigation Date: 2/11/2026

LetsDefend Event ID 182

Tags: Possible MalDoc in PDF was Detected, Incident Responder/T2

Investigation Date: 12/4/2024

LetsDefend Event ID 198

Tags: Unauthorized Access – Hack Tool Executed, Incident Responder/T2

Investigation Date: 11/5/2024

LetsDefend Event ID 292

Tags: Unauthorized Access to NTDS.dit File Detected, Incident Responder/T2

Investigation Date: 9/6/2024

LetsDefend Event ID 78

Tags: Meterpreter or Empire activity detected, Security Analyst/T1

Investigation Date: 8/29/2024

LetsDefend Event ID 89

Tags: Multiple 500 Resp Codes, Security Analyst/T1

Investigation Date: 8/23/2024