ag48665/soc-analyst-portfolio
GitHub: ag48665/soc-analyst-portfolio
一位初级安全运营中心分析师的作品集,记录了 Windows 日志分析、Sysmon 监控和 Sigma 检测规则等实操安全实验。
Stars: 0 | Forks: 0
# SOC Analyst 作品集
展示实操网络安全调查、检测工程、威胁狩猎和安全监控的作品集。
## 技能
* Windows 事件日志分析
* Sysmon
* Sigma 规则
* 威胁狩猎
* 事件响应
* 检测工程
* MITRE ATT&CK
* 安全监控
## 个人 SOC 实验室项目
### Windows 事件调查
* 成功登录分析(Event ID 4624)
* 失败登录分析(Event ID 4625)
### Sysmon 监控
* Sysmon 安装验证
* 进程创建监控
* PowerShell 执行检测
### 检测工程
* Sigma 失败登录检测
## 环境
### 宿主机
* Dell Latitude 9410
* Windows 11
* 16 GB RAM
### 虚拟机
* Windows 11 Enterprise Evaluation
* Oracle VirtualBox
## 学习目标
* Windows 事件日志
* Sysmon
* 威胁狩猎
* 检测工程
* 事件响应
## 涵盖的 MITRE ATT&CK 技术
* T1059 – Command and Scripting Interpreter
* T1059.001 – PowerShell
* T1110 – Brute Force
## 仓库结构
```
home-soc-lab/
├── windows-event-analysis.md
├── sysmon-installation.md
├── sysmon-process-creation.md
├── powershell-detection.md
├── sigma-failed-logon-detection.md
└── screenshots/
```
标签:OpenCanary, 个人作品集, 安全运营中心, 网络安全, 网络映射, 隐私保护