
Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no dependencies.
A free, fully offline interactive toolkit for Tier 1 SOC analysts — covering incident response, alert triage, threat hunting, and analyst onboarding. Zero dependencies. Single HTML file. Open in any browser.
Step-by-step interactive checklists for the most common incident types. Check off steps as you work — progress saves automatically.
Decision-tree flows for assessing, classifying, and escalating alerts — with YES/NO branching logic and clear escalation thresholds.
Structured hunting hypotheses with MITRE ATT&CK tags, data sources, and ready-to-use Splunk / Elastic queries.
A structured 4-week learning path for new Tier 1 analysts — 4 modules, 20 lessons, click-to-complete progress tracking.
| Week | Module |
|---|---|
| 1 | SOC Fundamentals — roles, toolchain, kill chain, ATT&CK |
| 2 | Alert Handling & Triage — severity, FP/TP, escalation |
| 3 | Investigation Skills — SIEM queries, process trees, threat intel |
| 4 | Incident Response Basics — NIST lifecycle, evidence, comms |
Option A — Use the live demo (no install needed): 👉 https://cross-samuel1.github.io/soc-analyst-hub/
Option B — Run locally:
git clone https://github.com/cross-samuel1/soc-analyst-hub.git
cd soc-analyst-hub
# Open soc_hub.html in any browser — no server required
Option C — Download directly:
Click soc_hub.html → Download raw file → open in browser.
soc-analyst-hub/
└── soc_hub.html # The entire app — HTML + CSS + JS in one file
└── README.md
Contributions welcome — new playbooks, additional hunt queries, updated techniques, or UI improvements.
git checkout -b add-new-playbooksoc_hub.htmlIdeas for contributions:
MIT License — free to use, modify, and distribute.
Samuel Cross
Built for the blue team community. If this helped you, give it a ⭐ — it helps others find it.