Skip to content

09 Enterprise SOC Projects

Welcome to:

Module 09 — Enterprise SOC Projects

You have now developed the core capabilities required by a modern Blue Team professional.

Throughout the previous modules, you learned how to:

Monitor
Detect
Triage
Investigate
Threat Hunt
Respond
Perform Forensics
Engineer Detections
Validate Defenses

Now it is time to bring everything together.

This module moves away from isolated exercises and places you into:

Enterprise
Security Scenarios

where there may be:

Multiple Users
Multiple Hosts
Multiple Alerts
Multiple Log Sources
Conflicting Evidence
Incomplete Information
Business Impact
Time Pressure

You will need to determine:

What Happened?
How Did It Happen?
Which Systems
Are Affected?
Which Accounts
Are Compromised?
What Is
the Attack Scope?
What Should
Be Contained?
What Evidence
Must Be Preserved?
Which Detection
Failed?
How Should
the Incident
Be Reported?

This is much closer to how real SOC investigations work.

By the end of this module, you will be able to:

  • investigate complex enterprise security incidents.

  • correlate alerts from multiple security technologies.

  • analyze identity, endpoint, network, email and cloud telemetry.

  • prioritize alerts based on business risk.

  • determine incident scope.

  • reconstruct attack timelines.

  • identify initial access.

  • investigate suspicious authentication.

  • investigate phishing incidents.

  • investigate endpoint compromise.

  • investigate malware activity.

  • investigate credential access.

  • investigate persistence.

  • investigate privilege escalation.

  • investigate lateral movement.

  • investigate cloud compromise.

  • investigate ransomware activity.

  • investigate data collection and exfiltration.

  • perform threat hunting during investigations.

  • preserve forensic evidence.

  • identify indicators of compromise.

  • map attacker activity to MITRE ATT&CK.

  • identify telemetry gaps.

  • identify detection gaps.

  • create new detection requirements.

  • recommend containment actions.

  • document incident findings.

  • prepare executive incident summaries.

  • build professional SOC investigation portfolios.

Each project follows:

Mission
Business Context
Initial Alert
Triage
Evidence Collection
Investigation
Correlation
Timeline
Scope
Containment
Recovery
Detection Improvement
Reporting

During these projects, assume the role of:

Enterprise
SOC Analyst

Depending on the project, you may also operate as:

Incident Responder
Threat Hunter
DFIR Analyst
Detection Engineer

The fictional enterprise environment contains:

Identity Platform
Windows Endpoints
Linux Servers
Email Platform
Corporate Network
Cloud Infrastructure
Web Applications
Security Monitoring
SIEM
EDR
Firewall
DNS
Proxy
Cloud Security Logs

You will investigate activity across these environments.

Projects may provide evidence such as:

Authentication Logs
Windows Event Logs
EDR Events
Process Creation Logs
PowerShell Logs
DNS Logs
Firewall Logs
Proxy Logs
Email Headers
Cloud Audit Logs
IAM Events
File Hashes
Memory Artifacts
Network Connections

The objective is not simply to find one suspicious event.

You must:

Correlate
Evidence

Project 01 — Enterprise Identity Compromise Investigation

Section titled “Project 01 — Enterprise Identity Compromise Investigation”

Investigate suspicious authentication activity involving a privileged enterprise user.

Initial alert:

Multiple Failed
Authentication Attempts
Successful Login
New Device
Privileged Account

Determine:

Was the Account
Compromised?
Where Did
the Login Originate?
Was MFA Used?
Was the Device
Known?
What Happened
After Authentication?
Were Privileges
Modified?
Were Other Accounts
Targeted?

Analyze:

Identity Logs
MFA Logs
VPN Logs
Cloud Authentication
Endpoint Logs
Threat Intelligence
Initial Alert
User Baseline
Source IP
Device
MFA
Authentication History
Post-Login Activity
Privilege Changes
Scope

Create:

Identity_Incident_Timeline.csv
Identity_Investigation.md
Identity_IOCs.csv
Identity_Containment_Plan.md

Project 02 — Phishing and Business Email Compromise

Section titled “Project 02 — Phishing and Business Email Compromise”

Investigate a suspicious email reported by an employee.

The message contains:

Urgent Request
External Sender
Authentication Link
Credential Collection

Shortly afterward:

Successful Login
from New Location

is observed.

Determine:

Was the Email
Malicious?
Who Received It?
Who Clicked?
Were Credentials
Entered?
Was the Account
Compromised?
Were Mailbox Rules
Created?
Was External
Forwarding Enabled?

Analyze:

Email Headers
Mail Gateway Logs
URL Reputation
Browser History
Authentication Logs
MFA Events
Mailbox Audit Logs

Potential chain:

Phishing Email
User Click
Credential Capture
Account Login
Mailbox Access
Persistence

Create:

Phishing_Analysis.md
Email_Header_Analysis.md
BEC_Timeline.csv
Affected_User_Register.csv
Containment_Actions.md

Project 03 — Endpoint Malware Investigation

Section titled “Project 03 — Endpoint Malware Investigation”

An endpoint security platform generates:

Suspicious
Process Execution

on a finance workstation.

Process chain:

winword.exe
powershell.exe
Unknown Executable

Determine:

What Started
the Process?
What Commands
Executed?
What Files
Were Created?
Was Persistence
Established?
Did the Host
Contact External
Infrastructure?
Were Credentials
Accessed?

Analyze:

EDR
Process Creation
PowerShell
File Events
Registry
Scheduled Tasks
Network Connections
DNS

Build:

Parent Process
Child Process
Command Line
File
Network

Create:

Endpoint_Investigation.md
Process_Tree.md
Malware_IOCs.csv
Endpoint_Timeline.csv
Containment_Plan.md

Project 04 — Credential Theft Investigation

Section titled “Project 04 — Credential Theft Investigation”

Security telemetry indicates unusual access to credential-related processes.

Shortly afterward:

Multiple
Remote Logins

appear across servers.

Determine:

Was Credential
Access Attempted?
Which Account
Was Exposed?
Was the Account
Reused?
Which Systems
Were Accessed?
Was Privilege
Escalation Achieved?

Analyze:

EDR
Memory Evidence
Authentication Logs
Windows Security Logs
Remote Access Logs
Identity Logs
Suspicious Process
Credential Access
Account Usage
Remote Authentication
Additional Hosts

Create:

Credential_Access_Investigation.md
Compromised_Accounts.csv
Affected_Hosts.csv
Credential_Incident_Timeline.csv

Project 05 — Lateral Movement Investigation

Section titled “Project 05 — Lateral Movement Investigation”

Multiple servers show remote administrative activity originating from a compromised workstation.

Determine:

Initial Host
Initial Account
Remote Protocol
Destination Systems
Privileges Used
Commands Executed
Persistence Created

Investigate:

RDP
SMB
SSH
Remote Services
PowerShell Remoting
User
Workstation A
Server B
Server C
Critical System

Create:

Lateral_Movement_Map.md
Host_Pivot_Register.csv
Authentication_Timeline.csv
Affected_Asset_Register.csv

A cloud security alert identifies:

Privileged
Cloud Authentication
from
Unexpected Source

followed by:

IAM Changes
Security Changes
Storage Access

Determine:

Which Identity
Was Compromised?
How Was It
Authenticated?
Which API Calls
Were Performed?
Were New
Credentials Created?
Were Security
Controls Modified?
Was Sensitive
Data Accessed?

Analyze:

Cloud Audit Logs
IAM Logs
Authentication Logs
Network Logs
Storage Access Logs
Security Findings
Authentication
Discovery
IAM Change
Security Change
Data Access

Create:

Cloud_Incident_Investigation.md
Cloud_API_Timeline.csv
IAM_Change_Register.csv
Cloud_Containment_Plan.md

Several endpoints suddenly begin generating:

Mass File
Modification Alerts

followed by:

Encrypted Files
Ransom Note
Service Disruption

Determine:

Initial Access
Patient Zero
Execution Method
Credential Access
Lateral Movement
Affected Hosts
Encryption Scope
Backup Impact
Data Exfiltration
Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Encryption

Do not assume:

Ransomware
=
Encryption Only

Investigate whether:

Data Theft
Occurred Before
Encryption

Create:

Ransomware_Investigation.md
Ransomware_Timeline.csv
Affected_Hosts.csv
Ransomware_IOCs.csv
Containment_and_Recovery.md

Project 08 — Data Exfiltration Investigation

Section titled “Project 08 — Data Exfiltration Investigation”

Network monitoring identifies:

Unusually Large
Outbound Transfer

from a server containing sensitive information.

Determine:

Which Data
Was Accessed?
Who Accessed It?
Was Data
Collected?
Was an Archive
Created?
Where Was
Data Sent?
How Much
Was Transferred?

Analyze:

File Access Logs
Endpoint Logs
Proxy Logs
Firewall
Network Flow
DNS
Cloud Storage Logs
Discovery
File Access
Collection
Archive
External Connection
Transfer

Create:

Exfiltration_Investigation.md
Data_Access_Register.csv
Network_Timeline.csv
Exfiltration_Evidence.md

Project 09 — Insider Threat Investigation

Section titled “Project 09 — Insider Threat Investigation”

A departing employee accesses an unusual volume of sensitive corporate information.

Determine:

What Data
Was Accessed?
Was Access
Authorized?
Was Data
Downloaded?
Was External
Storage Used?
Was Data
Uploaded Elsewhere?

Analyze:

Identity Logs
File Access
Endpoint Logs
USB Events
Cloud Storage
Email
Proxy

Do not assume:

Unusual Employee
Activity
=
Malicious Insider

Separate:

Observed Facts
Policy Violations
Risk Indicators
Intent

Intent may require investigation beyond technical telemetry.

Create:

Insider_Threat_Investigation.md
Data_Access_Timeline.csv
Evidence_Register.csv
Investigation_Findings.md

Project 10 — Multi-Stage Enterprise Intrusion

Section titled “Project 10 — Multi-Stage Enterprise Intrusion”

This is the primary integrated project.

Your SOC receives several apparently unrelated alerts:

Phishing Alert
Suspicious Login
PowerShell Alert
Rare Domain
Remote Authentication
Cloud IAM Change

Your task is to determine whether they represent:

Independent Events

or:

One Coordinated
Enterprise Intrusion
08:41
Phishing Email Delivered
08:47
User Opens Link
08:51
Payload Downloaded
08:54
PowerShell Executes
08:55
Rare Domain Connection
09:02
Scheduled Task Created
09:30
Credential Access Alert
10:10
Remote Authentication
10:35
Cloud Login
10:42
IAM Role Modified
11:05
Sensitive Storage Access
11:30
Large Outbound Transfer

Determine:

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Lateral Movement
Cloud Access
Collection
Exfiltration

Review all alerts.

Classify:

True Positive
Benign True Positive
False Positive
Requires Investigation

Determine:

Users
Authentication
MFA
IPs
Devices
Privileges

Analyze:

Processes
Commands
Files
Registry
Persistence
Network Connections

Analyze:

DNS
Proxy
Firewall
Network Flow
External Destinations

Analyze:

Cloud Authentication
IAM
API Calls
Storage
Logging Changes
Security Changes

Create a unified:

Enterprise
Attack Timeline

Identify:

Affected Users
Affected Hosts
Affected Servers
Cloud Resources
Sensitive Data

Map observed behaviors to:

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration

Recommend prioritized containment actions.

Example:

Disable
Compromised Account
Revoke Sessions
Isolate Host
Rotate Credentials
Block Malicious
Infrastructure
Remove Persistence
Secure Cloud IAM

Actual actions must depend on validated incident evidence and business requirements.

Ask:

Which Attacker
Actions Generated
No Alert?

Create:

Detection_Gap_Register.csv

with:

Behavior Telemetry Detection Result Gap Recommendation

Create new detection requirements for gaps identified during the investigation.

Examples:

Suspicious
Mailbox Rule
Scheduled Task
Persistence
Credential Access
Cloud Role Change
Large Data
Exfiltration

Design safe tests to validate your new detections.

Workflow:

Detection Gap
Detection Built
Controlled Simulation
Telemetry
Alert
SOC Investigation
Validated

Create:

01_Incident_Executive_Summary.md
02_Incident_Timeline.csv
03_Investigation_Workpaper.md
04_Affected_Assets.csv
05_Compromised_Accounts.csv
06_IOC_Register.csv
07_MITRE_ATTACK_Mapping.csv
08_Containment_Plan.md
09_Detection_Gap_Register.csv
10_Detection_Improvement_Plan.md
11_Purple_Team_Retest_Plan.md
12_Final_Incident_Report.md

Create:

Enterprise_SOC_Workpaper.md

with:

# Case Information
# Business Context
# Initial Alert
# Investigation Scope
# Users
# Hosts
# Cloud Resources
# Evidence Sources
# Initial Triage
# Identity Investigation
# Endpoint Investigation
# Network Investigation
# Cloud Investigation
# Digital Forensics
# Attack Timeline
# MITRE ATT&CK Mapping
# Incident Scope
# Containment
# Eradication
# Recovery
# Detection Gaps
# Recommended Detections
# Lessons Learned
# Analyst Conclusion

Create:

Master_Incident_Timeline.csv

with:

Timestamp Source User Host Event Evidence ATT&CK Significance

Create:

Affected_Assets.csv

with:

Asset Type Owner Criticality Evidence Status

Create:

Compromised_Identities.csv

with:

Identity Type Privilege Evidence First Seen Status

Create:

Enterprise_IOC_Register.csv

with:

IOC Type Source First Seen Confidence Action

Create:

Incident_ATTACK_Mapping.csv

with:

Tactic Technique Evidence User Host Confidence

Create:

Detection_Gap_Register.csv

with:

Gap Behavior Telemetry Existing Detection Recommendation Priority

Create:

Incident_Findings.csv

with:

Finding Evidence Interpretation Confidence Impact

Throughout every project maintain:

Observed Facts

separately from:

Analyst Hypotheses

Example:

Observed:

Account A
Authenticated
from IP X
at 10:35

Hypothesis:

Attacker Used
Stolen Credentials

Additional evidence is required to support the hypothesis.

Classify conclusions:

Confirmed
High Confidence
Moderate Confidence
Low Confidence
Unknown

When investigating:

Alert
Evidence
Context
Correlation
Hypothesis
Validation
Conclusion

Avoid:

Alert
Assumption
Conclusion

Consider:

Asset Criticality
Identity Privilege
Attack Scope
Data Sensitivity
Persistence
Business Impact
Threat Capability

Escalation may involve:

SOC Tier 2
Incident Response
DFIR
Threat Hunting
Cloud Security
Identity Team
Network Team
Management
Legal / Compliance

depending on the incident.

When evidence is extensive, prioritize:

Active Threat
Privileged Identity
Critical Assets
Persistence
Credential Access
Lateral Movement
Data Exfiltration

For major incidents preserve:

Logs
Disk
Memory
Cloud Audit Data
Email Evidence
Network Evidence
Security Alerts

according to organizational procedures.

A SOC analyst must communicate differently with:

Technical Teams
Incident Command
Management

Include:

Indicators
Processes
Accounts
Hosts
Network Activity
Current Scope

Include:

What Happened?
What Is Affected?
Business Impact?
Current Risk?
Containment Status?
Next Actions?

Create:

Executive_Incident_Summary.md

with:

# Incident
# Business Impact
# Current Scope
# Key Findings
# Containment Status
# Remaining Risk
# Recovery Status
# Required Management Actions

Every project should ask:

What Could
We Detect Better
Next Time?

Convert investigation findings into:

New Detection
Detection Tuning
Telemetry Improvement
Threat Hunt
Runbook Improvement

After identifying an IOC or behavior:

Incident Finding
Enterprise Hunt

Example:

Scheduled Task
Found on Host A
Search All Hosts
for Similar Tasks

After building a detection:

Detection
Controlled Test
Validation

This closes the defensive feedback loop.

Threat Intelligence
Detection
SOC Monitoring
Incident
Forensics
Threat Hunting
Detection Engineering
Purple Team
Improved Defense

These projects should become part of your:

Blue Team
Portfolio

A strong portfolio can contain:

Investigation Reports
Incident Timelines
Detection Rules
Sigma Rules
Threat Hunt Reports
ATT&CK Mapping
Forensic Analysis
Purple Team Reports
Executive Summaries

Create:

SOC-Portfolio/
├── 01-Identity-Investigation/
├── 02-Phishing-BEC/
├── 03-Endpoint-Malware/
├── 04-Credential-Theft/
├── 05-Lateral-Movement/
├── 06-Cloud-Compromise/
├── 07-Ransomware/
├── 08-Data-Exfiltration/
├── 09-Insider-Threat/
└── 10-Enterprise-Intrusion/

Your portfolio should demonstrate:

I Can
Investigate
I Can
Correlate Evidence
I Can
Build Timelines
I Can
Determine Scope
I Can
Map ATT&CK
I Can
Recommend Containment
I Can
Improve Detections
I Can
Communicate Findings

You should now be able to answer:

  1. How would you investigate a compromised privileged account?

  2. How would you investigate a phishing email?

  3. How would you determine whether phishing resulted in account compromise?

  4. How would you analyze a suspicious process tree?

  5. How would you investigate PowerShell execution?

  6. How would you identify persistence?

  7. How would you investigate credential theft?

  8. How would you identify lateral movement?

  9. How would you investigate a compromised cloud identity?

  10. How would you investigate ransomware?

  11. How would you determine whether data was exfiltrated?

  12. How would you build an incident timeline?

  13. How would you determine incident scope?

  14. How would you preserve forensic evidence?

  15. How would you map activity to MITRE ATT&CK?

  16. How would you distinguish facts from hypotheses?

  17. How would you identify detection gaps?

  18. How would you convert incident findings into detection requirements?

  19. How would you validate a new detection?

  20. How would you communicate findings to management?

Enterprise SOC investigations are rarely:

One Alert
One Answer

They are usually:

Many Alerts
Many Evidence Sources
Many Entities
Correlation
Timeline
Attack Story

Remember:

Alert
Incident
IOC
Complete Investigation
Account Used
Human Attribution
Detection Triggered
Incident Fully Detected
Data Accessed
Data Exfiltrated
Finding
Conclusion

until supported by evidence.

The professional workflow is:

Detect
Investigate
Correlate
Scope
Contain
Recover
Improve

Completing these projects prepares you for roles such as:

SOC Analyst
SOC Analyst Tier 2
Cybersecurity Analyst
Blue Team Analyst
Incident Response Analyst
DFIR Analyst
Threat Hunter
Detection Engineer
Cloud SOC Analyst

During interviews, you should be able to describe:

A Security Alert
How You
Investigated It
What Evidence
You Used
How You
Built the Timeline
How You
Determined Scope
How You
Recommended Containment
How You
Improved Detection

The goal of this module is to move you from:

I Understand
SOC Concepts

to:

I Can Perform
Enterprise SOC
Investigations

➡️ Next: GoHackersCloud Labs — Enterprise SOC Investigation Labs

You have now completed the core learning modules for the Blue Team / SOC learning path.

The next stage is hands-on practice.

You will move from:

Learning
How SOC Teams Work

to:

Working
Like a SOC Analyst

through structured enterprise labs covering:

Alert Triage
Identity Investigation
Phishing Investigation
Endpoint Investigation
Threat Hunting
Incident Response
Digital Forensics
Detection Engineering
Purple Team Validation
Enterprise Incident Investigation

Each lab will require you to:

Investigate
Collect Evidence
Build Timeline
Reach Conclusion
Document Findings

➡️ Next: GoHackersCloud Labs — Enterprise SOC Investigation Labs