ag48665/soc-analyst-portfolio

GitHub: ag48665/soc-analyst-portfolio

一位初级安全运营中心分析师的作品集,记录了 Windows 日志分析、Sysmon 监控和 Sigma 检测规则等实操安全实验。

Stars: 0 | Forks: 0

# SOC Analyst 作品集 展示实操网络安全调查、检测工程、威胁狩猎和安全监控的作品集。 ## 技能 * Windows 事件日志分析 * Sysmon * Sigma 规则 * 威胁狩猎 * 事件响应 * 检测工程 * MITRE ATT&CK * 安全监控 ## 个人 SOC 实验室项目 ### Windows 事件调查 * 成功登录分析(Event ID 4624) * 失败登录分析(Event ID 4625) ### Sysmon 监控 * Sysmon 安装验证 * 进程创建监控 * PowerShell 执行检测 ### 检测工程 * Sigma 失败登录检测 ## 环境 ### 宿主机 * Dell Latitude 9410 * Windows 11 * 16 GB RAM ### 虚拟机 * Windows 11 Enterprise Evaluation * Oracle VirtualBox ## 学习目标 * Windows 事件日志 * Sysmon * 威胁狩猎 * 检测工程 * 事件响应 ## 涵盖的 MITRE ATT&CK 技术 * T1059 – Command and Scripting Interpreter * T1059.001 – PowerShell * T1110 – Brute Force ## 仓库结构 ``` home-soc-lab/ ├── windows-event-analysis.md ├── sysmon-installation.md ├── sysmon-process-creation.md ├── powershell-detection.md ├── sigma-failed-logon-detection.md └── screenshots/ ```
标签:OpenCanary, 个人作品集, 安全运营中心, 网络安全, 网络映射, 隐私保护