Difficulty
N/A
Published Date
June 19, 2026
Summary
Page linking to all of my writeups for the SOC Analyst Tier 1 in CyberDefenders
Tags
CollectionsCyberDefendersDefensive
Build your foundational skills to monitor, detect, and escalate security alerts. This track includes essential tools, basic log analysis, and introductory incident response labs.
The SOC Analyst Tier 1 Track in CyberDefenders is the first Job Role-Based track in the platform, and it introduces students to foundational skills across Network Forensics, Threat Intel, Endpoint Forensics, Threat Hunting, and Cloud Forensics. In this page, you will find a collection of all writeups for all labs included in this track, completed around late June 2026.
Verify my completion achievement: CyberDefenders | SOC Analyst Tier 1 Track Completion
Level 1
Build your ability to identify and respond to basic security incidents.
Lab Name | Summary | Writeup |
JetBrains | Analyze network traffic using Wireshark to identify web server exploitation, extract attacker IOCs and persistence mechanisms, and map attack techniques to MITRE ATT&CK. | |
RetailBreach | Investigate network traffic with Wireshark to identify attacker TTPs, extract XSS payloads and session tokens, and determine exploited web application vulnerabilities. | |
AWSRaid | Investigate AWS CloudTrail logs using Splunk to identify unauthorized access, analyze configuration changes, and detect persistence mechanisms. | |
PoisonedCredentials | Analyze network traffic for LLMNR/NBT-NS poisoning attacks using Wireshark to identify the rogue machine, compromised accounts, and affected systems. |
Level 2
Develop essential skills in malware detection and forensics for endpoint devices.
Lab Name | Summary | Writeup |
PsExec Hunt | Analyze SMB traffic in a PCAP file using Wireshark to identify PsExec lateral movement, compromised systems, user credentials, and administrative shares. | |
Tomcat Takeover | Analyze network traffic using Wireshark's custom columns, filters, and statistics to identify suspicious web server administration access and potential compromise. | |
GrabThePhisher | Analyze a cryptocurrency phishing kit to identify exfiltration methods, extract critical IOCs, and gather threat actor intelligence using local logs and Telegram APIs. | |
Yellow RAT | Analyze malware artifacts using threat intelligence platforms like VirusTotal to identify IOCs, C2 servers, and understand adversary tactics. | |
IcedID | Investigate IcedID malware using VirusTotal and threat intelligence platforms to identify IOCs, associated threat actors, and execution mechanisms. | |
The Crime | Utilize ALEAPP to analyze Android device artifacts, reconstructing a victim's financial details, movements, and communication patterns. | |
Ramnit | Analyze a memory dump using Volatility to identify a malicious process, extract network IOCs, file hash, and compilation timestamp, correlating with external threat intelligence. |
Level 3
Master foundational tools for investigating suspicious activity and data breaches.
Lab Name | Summary | Writeup |
DanaBot | Analyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes. | |
XXE Infiltration | Analyze PCAP data using Wireshark to identify XXE vulnerabilities, extract compromised credentials, and detect web shell uploads for persistence. | |
REvil - GOLD SOUTHFIELD | Analyze Sysmon logs in Elastic SIEM to investigate REvil ransomware attack behaviors, decode recovery sabotage commands, and identify IOCs including the C2 onion domain. | |
Red Stealer | Analyze a suspicious executable using VirusTotal and MalwareBazaar to extract IOCs, identify C2 infrastructure, MITRE ATT&CK techniques, and privilege escalation mechanisms. | |
Oski | Analyze a sandbox report using Any.Run to identify Stealc malware behavior, extract configuration details, and map observed tactics to MITRE ATT&CK. | |
RedLine | Employ Volatility to analyze a memory dump, identifying suspicious processes, network IOCs, memory protections, and attacker's command-and-control infrastructure. | |
Volatility Traces | Analyze a memory dump using Volatility to identify malicious processes, persistence mechanisms, defense evasion techniques, and map them to MITRE ATT&CK. |
Level 4
Strengthen your knowledge of common cyber threats and incident response techniques.
Lab Name | Summary | Writeup |
AzureHunt | Correlate Azure AD, Activity, and Blob Storage logs in Elastic Stack to reconstruct an attack timeline, identifying initial access, lateral movement, persistence, and data exfiltration. | |
Amadey - APT-C-36 | Reconstruct Amadey Trojan behavior by analyzing memory dumps with Volatility3 to identify malicious processes, C2 communications, payload delivery, and persistence mechanisms. | |
XMRig | Reconstruct attacker methods on a Linux system by analyzing a disk image, recovering deleted files with Photorec, and correlating logs, command history, and configuration files. | |
Andromeda Bot - UNC4210 | Analyze memory images and event logs using MemProcFS, EvtxECmd, and Timeline Explorer to identify Andromeda bot IOCs, reconstruct its infection timeline, and attribute it to an APT group. | |
Reveal | Reconstruct a multi-stage attack by analyzing Windows memory dumps using Volatility 3, identifying malicious processes, command lines, and correlating findings with threat intelligence. | |
3CX Supply Chain | Reconstruct the 3CX supply chain attack by analyzing compromised MSI and DLL artifacts to identify TTPs and attribute the incident to a threat actor. |