# Foundations: first SOC investigation workbook

SOC Foundations Bootcamp — ₹1,999; four live lessons, four labs, lifetime lab
access with eight launches per UTC calendar month. Practice between classes.

## Match a trainee or junior SOC posting

Company / role / original URL / location / date checked open:
Experience, qualifications, shifts and product requirements:

| Requirement | Included practice | My evidence / help used | Gap and next action |
| --- | --- | --- | --- |
| Explore SIEM data | Splunk First Steps | | |
| Read Windows activity | Reading Windows Logs | | |
| Investigate users and hosts | SPL Detective | | |
| Report and escalate | Insider Threat Investigation | | |

For each row mark demonstrated / guided practice / not yet demonstrated.
Separately record networking, Linux, EDR, other SIEM products, ticketing and
operational requirements. Malware, phishing C2 and Loki are outside this offer.

## Interview rehearsal

1. How did you find the relevant index, sources and time range?
2. Explain a Windows event you used. What does it not prove?
3. Explain your own SPL search and why you chose its fields.
4. Which benign explanation did you test?
5. Explain your insider-threat timeline and escalation in two minutes.

## Your independent follow-up

After the four labs, ask for a different Windows or insider-threat question.
The instructor supplies a supported scope/window: investigate whether a pattern
is isolated, compare available activity, test an alternative explanation and
write an escalation decision. Do not assume extra hosts or events exist.

Aim to finish with selected queries, an evidence timeline, one case study,
a handoff and a walkthrough you can explain. Revise after instructor feedback.

## Investigation evidence

Lab / date / attempt reference / assistance used (guided, independent or mixed):
Question and evidence needed to support or refute it:
Searches: SPL, source/index, time range/timezone, fields, selected events and why:
Timeline: time | host/user | event/source | significance | confidence:
Findings: established facts, affected scope, tested alternatives and unknowns:
Handoff: proposed priority and why, key evidence, next action and remaining questions:
Interview walkthrough: question → evidence → decision → limitations → next action.

Save these sections against the matching lab in https://portal.cymbytes.com/portfolio.
Capture evidence before the lab closes. Keep secrets and personal data out.
Save, then submit for instructor feedback. Sharing is optional.

## Follow-up submission

Record the instructor-assigned question, lab, actual evidence window/timezone,
assignment date, agreed deadline and help used. Use the existing monthly launch
allowance. Attempt without a walkthrough, tutor or generated answer; reference
documentation is allowed if disclosed. Ask for help if stuck and declare it.

Append clearly labelled Follow-up assessment sections to the same case study;
preserve the original. If guided and independent work coexist, mark mixed and
describe both. Submit for feedback on evidence, method, reasoning/limits and
handoff. This is formative instructor review, separate from platform scoring
and certificate criteria; independence is self-declared unless observed.

## Apply with accurate evidence

CV section: Practical projects / SOC lab investigations. Use only completed
work you can explain and a portfolio link you chose to publish. Lab training
is not employment, an internship or years of professional experience. Check
the vacancy is still open and assess the employer’s full eligibility criteria.
No interview, placement or professional job level is guaranteed.
