awesome-soc-analyst
We just collected useful resources for SOC analysts and SOC analyst candidates.
This repository is maintained by LetsDefend. Feel free to add new resources here.
Table of Contents
Books
- Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
- Blue Team Field Manual (BTFM)
- Applied Network Security Monitoring: Collection, Detection, and Analysis
- Blue Team Handbook: Incident Response Edition: A condensed field guide for the Cyber Security Incident Responder
- The Practice of Network Security Monitoring: Understanding Incident Detection and Response
- Jump-start Your SOC Analyst Career: A Roadmap to Cybersecurity Success
Malware Analysis
- VirusTotal - Analyse suspicious files, domains, IPs and URLs to detect malware and other breaches, automatically share them with the security community.
- Hybrid Analysis - This is a free malware analysis service for the community that detects and analyzes unknown threats using a unique Hybrid Analysis technology.
- YARA - YARA is a multi-platform program running on Windows, Linux and Mac OS X.
- Malware Analysis Fundamentals
- Cuckoo Sandbox - You can throw any suspicious file at it and in a matter of minutes Cuckoo will provide a detailed report outlining the behavior of the file when executed inside a realistic but isolated environment.
- IDA - IDA Pro as a disassembler is capable of creating maps of their execution to show the binary instructions that are actually executed by the processor in a symbolic representation.
- DOCGuard - Zero Miss for Office Malware Threats
- Immunity Debugger - Immunity Debugger is a dynamic analysis tool that allows executables to be analyzed at the assembly language level with reverse engineering techniques.
Practice Labs
- DetectionLab - DetectionLab is a repository containing a variety of Packer, Vagrant, Powershell, Ansible, and Terraform scripts that allow you to automate the process of bringing an ActiveDirectory environment online complete with logging and security tooling using a variety of different platforms.
- LetsDefend - Hands-on SOC Analyst training
- attack_range - The Splunk Attack Range is an open-source project maintained by the Splunk Threat Research Team. It builds instrumented cloud and local environments, simulates attacks, and forwards the data into a Splunk instance.
- BlueTeam.Lab - The goal of this project is to provide the red and blue teams with the ability to deploy an ad-hoc detection lab to test various attacks and forensic artifacts on the latest Windows environment and then to get a 'SOC-like' view into generated data.
Phishing Analysis
- Process Hacker - Great tool for monitoring the system and detecting suspicious situations. It’s also free.
- Procmon - Procmon(Process Monitor) tool is a useful tool that provides real-time information by monitoring the activities of processes on Windows.
- Volatility - Volatility is a tool that enables the analysis of memory dumps taken from a compromised machine during the incident response process.
- Wireshark - Wireshark is a tool that allows capturing, analyzing, and recording network packets passing through network interfaces on the system.
- BrowsingHistoryView - It gives you the history of different browsers in one table.
Network Log Sources
Network Devices Logs
Network devices can sometimes be targeted by attackers because network devices such as routers and switches are capable of packet routing. If the attacker interferes with the management of such a device and changes the existing lists, it may change the course and effect of the attack. It is useful to check the lists of network devices regularly to detect these situations. In addition, if there are logs produced by the device, such records should also be examined.
Linux Firewall Logs
UFW (Uncomplicated Firewall) is a firewall tool that allows us to perform port and firewall operations on both the console and GUI (graphical interface). It comes installed in Linux systems but must be activated. It performs operations just like other firewall software. When analyzing Linux systems, Linux firewall logs should be examined.
SMB Logs
Server Message Block (SMB) is a network protocol that enables the communication between server and client. The SMB protocol provides access to shared files, network communication, printer sharing, and various connections. SMB connections are frequently used on Windows systems. Its importance is noticed especially in domain environments. The SMB protocol, which is seen as an important source of vulnerability for attackers, needs to be followed carefully by the analyst on the defense side. Therefore, SMB protocol logs should be examined with high priority.