SOC & Alert Triage
Practical workflows for validating alerts, investigating Windows and Linux activity, and documenting decisions for the next analyst.
Triage a SOC Alert â
Investigate Windows Sign-In Activity â
Trace a Process with Sysmon â
Triage Linux SSH and Sudo Activity â
Build a Small SOC Lab with Wazuh â
Use KQL for First-Line Investigations â
Investigate Entra ID Sign-In Alerts â
Triage DNS and Outbound Traffic with Zeek â
Investigate a Microsoft Defender Endpoint Alert â
Triage a Phishing Email â