{"id":10,"date":"2023-01-24T07:56:05","date_gmt":"2023-01-24T07:56:05","guid":{"rendered":"https:\/\/victorcoil.tech\/?page_id=10"},"modified":"2026-06-18T22:57:58","modified_gmt":"2026-06-18T22:57:58","slug":"tryhackme-writeups","status":"publish","type":"page","link":"https:\/\/victorcoil.tech\/?page_id=10","title":{"rendered":"SOC Investigation Note Samples"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a more structured timeline approach and incorporate advice from working SMEs and practitioners.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Let&#8217;sDefend notes, there will be tags for T1\/T2 or for Security Analyst\/Incident Responder. These tags indicate which cases I handle with basic triage (T1) or with deep-dive, comprehensive investigations (T2).<\/p>\n\n\n\n<div class=\"wp-block-group has-zeever-bgsoft-background-color has-background is-layout-constrained wp-container-core-group-is-layout-8fda3007 wp-block-group-is-layout-constrained\" style=\"padding-top:100px;padding-bottom:100px\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group zeever-animate zeever-move-up zeever-delay-3 is-layout-constrained wp-container-core-group-is-layout-e0c1be90 wp-block-group-is-layout-constrained\" style=\"padding-top:40px\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-style-customborderbottomhover zeever-animate zeever-move-up zeever-delay-1 has-background is-layout-flow wp-block-column-is-layout-flow\" style=\"background-color:#121212;padding-top:50px;padding-right:40px;padding-bottom:50px;padding-left:40px\">\n<h2 class=\"wp-block-heading has-text-align-left has-zeever-primary-color has-text-color has-heading-3-font-size\" style=\"margin-top:20px;font-style:normal;font-weight:600\"><a href=\"https:\/\/victorcoil.tech\/?page_id=1163\" target=\"_blank\" rel=\"noopener\" title=\"\">LetsDefend Event ID 278<\/a><\/h2>\n\n\n\n<p class=\"has-text-align-left has-zeever-bodytext-color has-text-color wp-block-paragraph\">Tags: Suspicious Base64 Encoding\/Decoding Commands Detected, Incident Responder\/T2<br><br>Investigation Date: 2\/11\/2026<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-style-customborderbottomhover zeever-animate zeever-move-up zeever-delay-3 has-background is-layout-flow wp-block-column-is-layout-flow\" style=\"background-color:#121212;padding-top:50px;padding-right:40px;padding-bottom:50px;padding-left:40px\">\n<h2 class=\"wp-block-heading has-text-align-left has-zeever-primary-color has-text-color has-heading-3-font-size\" style=\"margin-top:20px;font-style:normal;font-weight:600\"><\/h2>\n\n\n\n<p class=\"has-text-align-left has-zeever-bodytext-color has-text-color wp-block-paragraph\"><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-style-customborderbottomhover zeever-animate zeever-move-up zeever-delay-5 has-background is-layout-flow wp-block-column-is-layout-flow\" style=\"background-color:#121212;padding-top:50px;padding-right:40px;padding-bottom:50px;padding-left:40px\">\n<h2 class=\"wp-block-heading has-text-align-left has-zeever-primary-color has-text-color has-heading-3-font-size\" style=\"margin-top:20px;font-style:normal;font-weight:600\"><\/h2>\n\n\n\n<p class=\"has-text-align-left has-zeever-bodytext-color has-text-color wp-block-paragraph\"><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a more structured timeline approach and incorporate advice from working SMEs and practitioners. For Let&#8217;sDefend notes, there will be tags for T1\/T2 or for Security Analyst\/Incident Responder. These tags indicate which cases I handle with basic triage (T1) or with deep-dive, comprehensive investigations (T2). LetsDefend Event<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"class_list":["post-10","page","type-page","status-publish","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/victorcoil.tech\/?page_id=10\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"SOC Investigation Note Samples - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta property=\"og:description\" content=\"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/victorcoil.tech\/?page_id=10\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-01-24T07:56:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-18T22:57:58+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"SOC Investigation Note Samples - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta name=\"twitter:description\" content=\"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=10#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/victorcoil.tech\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=10#listItem\",\"name\":\"SOC Investigation Note Samples\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=10#listItem\",\"position\":2,\"name\":\"SOC Investigation Note Samples\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=10#webpage\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=10\",\"name\":\"SOC Investigation Note Samples - Victor Coil | Security Operations & Detection Engineering\",\"description\":\"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=10#breadcrumblist\"},\"datePublished\":\"2023-01-24T07:56:05+00:00\",\"dateModified\":\"2026-06-18T22:57:58+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/\",\"name\":\"Victor Coil Portfolio\\\/Project Archive\",\"description\":\"Cybersecurity Projects\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"SOC Investigation Note Samples - Victor Coil | Security Operations & Detection Engineering","description":"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a","canonical_url":"https:\/\/victorcoil.tech\/?page_id=10","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/victorcoil.tech\/?page_id=10#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","position":1,"name":"Home","item":"https:\/\/victorcoil.tech","nextItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=10#listItem","name":"SOC Investigation Note Samples"}},{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=10#listItem","position":2,"name":"SOC Investigation Note Samples","previousItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","name":"Home"}}]},{"@type":"WebPage","@id":"https:\/\/victorcoil.tech\/?page_id=10#webpage","url":"https:\/\/victorcoil.tech\/?page_id=10","name":"SOC Investigation Note Samples - Victor Coil | Security Operations & Detection Engineering","description":"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/victorcoil.tech\/#website"},"breadcrumb":{"@id":"https:\/\/victorcoil.tech\/?page_id=10#breadcrumblist"},"datePublished":"2023-01-24T07:56:05+00:00","dateModified":"2026-06-18T22:57:58+00:00"},{"@type":"WebSite","@id":"https:\/\/victorcoil.tech\/#website","url":"https:\/\/victorcoil.tech\/","name":"Victor Coil Portfolio\/Project Archive","description":"Cybersecurity Projects","inLanguage":"en-US","publisher":{"@id":"https:\/\/victorcoil.tech\/#person"}}]},"og:locale":"en_US","og:site_name":"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects","og:type":"article","og:title":"SOC Investigation Note Samples - Victor Coil | Security Operations &amp; Detection Engineering","og:description":"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a","og:url":"https:\/\/victorcoil.tech\/?page_id=10","article:published_time":"2023-01-24T07:56:05+00:00","article:modified_time":"2026-06-18T22:57:58+00:00","twitter:card":"summary_large_image","twitter:title":"SOC Investigation Note Samples - Victor Coil | Security Operations &amp; Detection Engineering","twitter:description":"These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC. These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a"},"aioseo_meta_data":{"post_id":"10","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2023-06-14 22:20:40","updated":"2026-06-21 16:49:46","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/victorcoil.tech\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tSOC Investigation Note Samples\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/victorcoil.tech"},{"label":"SOC Investigation Note Samples","link":"https:\/\/victorcoil.tech\/?page_id=10"}],"_links":{"self":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/10","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10"}],"version-history":[{"count":18,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/10\/revisions"}],"predecessor-version":[{"id":1177,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/10\/revisions\/1177"}],"wp:attachment":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}