{"id":25831517,"url":"https://github.com/st0pp3r/awesome-soc-analyst","last_synced_at":"2026-03-05T06:31:08.424Z","repository":{"id":285514082,"uuid":"924315403","full_name":"st0pp3r/awesome-soc-analyst","owner":"st0pp3r","description":"Online resources related to SOC Analysts. Incident investigation reference material, blogs, newsletters, good reads, books, trainings, podcasts, Twitter/X accounts and a set of tools relevant to the role of SOC analyst.","archived":false,"fork":false,"pushed_at":"2026-02-14T20:12:40.000Z","size":271,"stargazers_count":43,"open_issues_count":0,"forks_count":3,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-03-03T20:58:01.709Z","etag":null,"topics":["awesome","awesome-list","cybersecurity","security","security-tools","soc","soc-analyst","soc-analysts"],"latest_commit_sha":null,"homepage":"","language":"HTML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"cc0-1.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/st0pp3r.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"contributing.md","funding":null,"license":"LICENSE","code_of_conduct":"code-of-conduct.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-01-29T19:33:39.000Z","updated_at":"2026-03-03T12:21:05.000Z","dependencies_parsed_at":null,"dependency_job_id":"e91d3640-faba-4418-ac4e-4774c9da6fa1","html_url":"https://github.com/st0pp3r/awesome-soc-analyst","commit_stats":null,"previous_names":["st0pp3r/awesome-soc-analyst"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/st0pp3r/awesome-soc-analyst","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/st0pp3r%2Fawesome-soc-analyst","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/st0pp3r%2Fawesome-soc-analyst/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/st0pp3r%2Fawesome-soc-analyst/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/st0pp3r%2Fawesome-soc-analyst/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/st0pp3r","download_url":"https://codeload.github.com/st0pp3r/awesome-soc-analyst/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/st0pp3r%2Fawesome-soc-analyst/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30112218,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-05T03:40:26.266Z","status":"ssl_error","status_checked_at":"2026-03-05T03:39:15.902Z","response_time":93,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["awesome","awesome-list","cybersecurity","security","security-tools","soc","soc-analyst","soc-analysts"],"created_at":"2025-02-28T20:34:18.138Z","updated_at":"2026-03-05T06:31:08.406Z","avatar_url":"https://github.com/st0pp3r.png","language":"HTML","funding_links":[],"categories":["Other Lists"],"sub_categories":["🖥️ SIEM/SOC/PurpleTeam related:","TeX Lists"],"readme":"# Awesome SOC Analyst [![Awesome](https://awesome.re/badge.svg)](https://awesome.re) \n[![URL Check](https://github.com/st0pp3r/awesome-soc-analyst/actions/workflows/url_check.yml/badge.svg)](https://github.com/st0pp3r/awesome-soc-analyst/actions/workflows/url_check.yml/badge.svg) [![Create Bookmarks File](https://github.com/st0pp3r/awesome-soc-analyst/actions/workflows/create_bookmarks.yml/badge.svg)](https://github.com/st0pp3r/awesome-soc-analyst/actions/workflows/create_bookmarks.yml)[![Spell Check](https://github.com/st0pp3r/awesome-soc-analyst/actions/workflows/spell_check.yml/badge.svg)](https://github.com/st0pp3r/awesome-soc-analyst/actions/workflows/spell_check.yml)\n\nOnline resources for SOC Analysts. Resources related to incident investigation, blogs, newsletters, good reads, books, trainings, podcasts, Twitter/X accounts and a set of online tools for day-to-day investigations. \nThe repo generates a bookmark file for easy import to your browser.\n\nI will mostly include resources that are tailored as much as possible to the role of the SOC Analyst and not the field of cyber security in general.\n\n**Contributions are welcome!**\n\n## Contents\n\n- [Resources and Reference Material](#resources-and-reference-material) - Various reference materials, frameworks, and guidelines for cyber defense.\n- [Attack Reference Material](#attack-reference-material) - Attack-specific reference materials for understanding tactics, techniques, and procedures.\n- [Event Log References](#event-log-references) - Vendor documentation and references for event logs.\n- [Blogs](#blogs) - Blogs that offer valuable insights and updates in security and incident handling.\n- [Good Reads](#good-reads) - Recommended reading materials for expanding knowledge in cyber defense.\n- [Newsletters](#newsletters) - Newsletters that provide curated content and updates in the cyber security space.\n- [Podcasts](#podcasts) - Podcasts related to cyber defense, incident response, and security topics.\n- [Books](#books) - Books focused on improving knowledge and skills in cyber defense and security.\n- [Training and Certifications](#training-and-certifications) - Training programs and certifications relevant to security operations and incident response.\n- [Twitter/X](#twitterx) - Notable Twitter/X accounts to follow for security updates and news.\n- [Interview Questions](#interview-questions) - Sample interview questions for cybersecurity roles, particularly for SOC analysts.\n- [Tools](#tools) - A collection of essential tools for security operations, categorized for easy reference:\n    - [Sandboxes](#sandboxes) - Sandboxes for safe malware analysis and testing.\n    - [IOC Lookups](#ioc-lookups) - Tools for looking up Indicators of Compromise (IOCs).\n    - [Emails](#emails) - Tools for analyzing and investigating email headers and email-related data.\n    - [Multifunctional LookUp Services](#multifunctional-lookup-services) - Tools for searching multiple data points (IP, URL, Domain, etc.).\n    - [Fingerprinting](#fingerprinting) - Tools for identifying and fingerprinting devices and services.\n    - [Network Scanning](#network-scanning) - Tools for scanning and analyzing network traffic.\n    - [SSL/TLS](#ssltls) - Tools for scanning and analyzing SSL/TLS configurations.\n    - [Website Scan](#website-scan) - Tools for scanning websites for security vulnerabilities.\n    - [CMS Scan](#cms-scan) - Tools for scanning Content Management Systems (CMS) for vulnerabilities.\n    - [URL](#url) - Tools for analyzing and investigating URLs.\n    - [DNS](#dns) - Tools for analyzing and querying DNS records.\n    - [MAC](#mac) - Tools for looking up and identifying MAC addresses.\n    - [ASN](#asn) - Tools for querying ASN information.\n    - [Browser Extension](#browser-extension) - Browser extensions for security professionals.\n    - [User Agent](#user-agent) - Tools for investigating and analyzing User Agent data.\n    - [USB and PCI](#usb-and-pci) - Tools related to USB and PCI devices for security analysis.\n    - [EXE Lookup](#exe-lookup) - Tools for analyzing executable files.\n    - [Certificate](#certificate) - Tools for analyzing certificates.\n    - [Hash](#hash) - Tools for hashing and investigating file hashes.\n    - [Misc Tools](#misc-tools) - Miscellaneous tools useful for various security tasks.\n    - [Data Manipulation Online Tools](#data-manipulation-online-tools) - Online tools for data manipulation and analysis.\n\n### Resources and Reference Material\n- [MITRE ATT\u0026CK®](https://attack.mitre.org/) - MITRE ATT\u0026CK knowledge base of adversary tactics and techniques.\n- [MITRE D3fend](https://d3fend.mitre.org/) - A knowledge base of cybersecurity countermeasures\n- [Cyber Kill Chain | Lockheed Martin](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html) - Model for identification and prevention of cyber intrusions activity.\n- [Blue Team Notes | Purp1eW0lf](https://github.com/Purp1eW0lf/Blue-Team-Notes)\n- [CVE](https://cve.mitre.org/) - Vulnerability database.\n- [Command Line Arguments Docs| ss64](https://ss64.com/) - Command line arguments explanations.\n- [Port Information | Speedguide.net](https://www.speedguide.net/ports.php) - Port information and common apps.\n- [LOLBAS (Living Off The Land Binaries and Scripts)](https://lolbas-project.github.io/) - Collection of legitimate binaries and scripts abused by attackers.\n- [WTFBins](https://wtfbins.wtf/) - Binaries that behaves exactly like malware, except, somehow, they are not.\n- [LOLDrivers](https://loldrivers.io/) - Database of drivers used by adversaries to bypass security controls and carry out attacks.\n- [GTFOBins](https://gtfobins.github.io/) - Collection binaries that can be used to bypass local security restrictions in misconfigured systems.\n- [LOLRMM](https://lolrmm.io/) - Repository of Remote Monitoring and Management (RMM) software that attackers abuse.\n- [LOLOLFarm](https://lolol.farm/) - Database of LOL (Living Off The Land) techniques used.\n- [Email Headers IANA](https://www.iana.org/assignments/message-headers/message-headers.xhtml) - IANA Email headers reference.\n- [DKIM, DMARC, SPF](https://github.com/nicanorflavier/spf-dkim-dmarc-simplified) - Simplified explanation of DKIM, DMARC, SPF.\n- [Kerberos Protocol | hackndo](https://en.hackndo.com/kerberos/) - Explanation of Keberos protocol.\n- [Service Principal Name (SPN) | hackndo](https://en.hackndo.com/service-principal-name-spn/) - Explanation of SPN.\n\n### Attack Reference Material\n- [ADSecurity AD Attacks](https://adsecurity.org/?page_id=4031) - Attacks on Active Directory.\n- [Password Spraying | hackndo](https://en.hackndo.com/password-spraying-lockout/) - Explanation of password spraying.\n- [Pass-The-Hash | hackndo](https://en.hackndo.com/pass-the-hash/) - Explanation of pass the hash attack.\n- [Over Pass-The-Hash](https://medium.com/r3d-buck3t/play-with-hashes-over-pass-the-hash-attack-2030b900562d) - Explanation of over pass the hash attack.\n- [Pass the ticket](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1550-use-alternate-authentication-material/pass-the-ticket) - Explanation of over pass the ticket attack.\n- [Kerberoasting | adsecurity](https://adsecurity.org/?p=3458) - Explanation of kerberoasting attack.\n- [Kerberoasting | hackndo](https://en.hackndo.com/kerberoasting/) - Explanation of kerberoasting attack.\n- [Kerberos Unconstrained Delegation | hackndo](https://en.hackndo.com/constrained-unconstrained-delegation/) - Explanation of Kerberos unconstained delegation.\n- [AS_REP Roasting | hackndo](https://en.hackndo.com/kerberos-asrep-roasting/) - Explanation of as_rep roasting attack.\n- [Golden Ticket | hackndo](https://en.hackndo.com/kerberos-silver-golden-tickets/) - Explanation of golden ticket attack.\n- [Silver Ticket | hackndo](https://en.hackndo.com/kerberos-silver-golden-tickets/) - Explanation of silver ticket attack.\n- [Skeleton Key | adsecurity](https://adsecurity.org/?p=1255) - Explanation of Skeleton Key attack.\n- [NTLM Relay | hackndo](https://en.hackndo.com/ntlm-relay/) - Explanation of NTLM Relay.\n- [LLMNR Poisoning](https://medium.com/@rymak/llmnr-poisoning-an-attack-on-the-active-directory-of-an-organization-9907bf0498ff) - Explanation of LLMNR Poisoning.\n- [DCSync | adsecurity](https://adsecurity.org/?p=1729) - Explanation of DCSync attack.\n- [DNS Tunneling | unit42](https://unit42.paloaltonetworks.com/dns-tunneling-how-dns-can-be-abused-by-malicious-actors/) - Simple example of DNS tunneling and how it is abused.\n- [DNS DGA | cybereason](https://www.cybereason.com/blog/what-are-domain-generation-algorithms-dga) - Nice examples of DGA variants.\n\n### Event Log References\n- [Windows Event IDs and Audit Policies](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/advanced-security-audit-policy-settings)\n- [Windows Security Log Event IDs Encyclopedia](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/default.aspx?i=j)\n- [Windows Logon Types](https://learn.microsoft.com/en-us/windows-server/identity/securing-privileged-access/reference-tools-logon-types)\n- [Windows Logon Failure Codes](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625)\n- [Azure SigninLogs Schema](https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/signinlogs)\n- [Azure SigninLogs Risk Detection](https://learn.microsoft.com/en-us/graph/api/resources/riskdetection?view=graph-rest-1.0)\n- [AADSTS Error Codes](https://learn.microsoft.com/en-us/entra/identity-platform/reference-error-codes#aadsts-error-codes)\n- [Microsoft Errors Search](https://login.microsoftonline.com/error)\n- [Microsoft Entra authentication and authorization error codes](https://learn.microsoft.com/en-us/entra/identity-platform/reference-error-codes)\n- [Microsoft Defender Event IDs](https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus)\n- [Microsoft Defender for Cloud Alert References](https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference)\n- [Microsoft Defender for Identity Alert References](https://learn.microsoft.com/en-us/defender-for-identity/alerts-overview)\n- [Microsoft Defender XDR Schemas](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-schema-tables)\n- [Microsoft DNS Debug Event IDs](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn800669(v=ws.11)#dns-logging-and-diagnostics-1)\n- [Sysmon Event IDs](https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#events)\n- [Cisco ASA Event IDs](https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html)\n- [Palo Alto PAN-OS Log Fields](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions)\n- [Palo Alto PAN-OS Threat Categories](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration/threat-prevention/threat-signature-categories)\n- [Palo Alto PAN-OS Applications](https://applipedia.paloaltonetworks.com/)\n- [FortiGate FortiOS Log Types and Subtypes](https://docs.fortinet.com/document/fortigate/7.6.1/fortios-log-message-reference/160372/list-of-log-types-and-subtypes)\n- [FortiGate FortiOS Log Fields](https://docs.fortinet.com/document/fortigate/7.6.1/fortios-log-message-reference/357866/log-message-fields)\n- [FortiGate FortiGuard Encyclopedia](https://www.fortiguard.com/encyclopedia?type=ips)\n- [GCP Threat Detection Findings](https://cloud.google.com/security-command-center/docs/concepts-security-sources#threats)\n- [GuardDuty Finding Types](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-active.html)\n- [Barracuda Firewall Log Files Structure and Log Fields](https://campus.barracuda.com/product/cloudgenfirewall/doc/172623663/available-log-files-and-structure)\n- [Barracuda Web Security Gateway Log Fields](https://campus.barracuda.com/product/websecuritygateway/doc/168742383/syslog-and-the-barracuda-web-security-gateway/)\n- [Barracuda Web Application Firewall Log Format](https://campus.barracuda.com/product/webapplicationfirewall/doc/168312817/log-formats) and [Barracuda Web Application Firewall Log Formats](https://campus.barracuda.com/product/webapplicationfirewall/doc/168312823/exporting-log-formats)\n- [Check Point Firewall Log Fields](https://support.checkpoint.com/results/sk/sk144192)\n- [Cisco Umbrella Proxy Log Format](https://docs.umbrella.com/deployment-umbrella/docs/proxy-log-formats), [Cisco Umbrella DNS Log Format](https://docs.umbrella.com/deployment-umbrella/docs/dns-log-formats) and [Cisco Umbrella Content Categories](https://docs.umbrella.com/deployment-umbrella/docs/new-content-category-definitions)\n- [Cisco WSA Access Log Fields](https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_010111.html#con_1679851) and [Cisco WSA Filtering Categories](https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/datasheet_C78-718442.html)\n- [Cisco ESA Log Types](https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-0/user_guide/b_ESA_Admin_Guide_15-0/b_ESA_Admin_Guide_12_1_chapter_0100111.html)\n- [Juniper Junos OS Log Fields](https://www.juniper.net/documentation/us/en/software/junos/network-mgmt/topics/topic-map/system-logging-for-a-security-device.html)\n- [Imperva Log Fields](https://docs.imperva.com/bundle/cloud-application-security/page/more/log-file-structure.htm) and [Imperva Event Types](https://docs.imperva.com/bundle/v15.3-waf-system-events-reference-guide/page/63179.htm)\n- [Squid Log Fields and Log Types](https://wiki.squid-cache.org/SquidFaq/SquidLogs) and [Squid Log Format](https://wiki.squid-cache.org/Features/LogFormat)\n- [Suricata Log Format](https://docs.suricata.io/en/latest/output/eve/eve-json-format.html)\n- [ZScaler Web Log Format](https://help.zscaler.com/zia/nss-feed-output-format-web-logs), [ZScaler Firewall Log Format](https://help.zscaler.com/zia/nss-feed-output-format-firewall-logs), [ZScaler DNS Log Format](https://help.zscaler.com/zia/nss-feed-output-format-dns-logs) and [ZScaler URL Categories](https://help.zscaler.com/zia/about-url-categories).\n- [Broadcom Edge Secure Web Gateway (Bluecoat) Access Log Format](https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/edge-swg/7-4/getting-started/page-help-administration/page-help-logging/log-formats.html) and [Broadcom Edge Secure Web Gateway (Bluecoat) Categories](https://sitereview.bluecoat.com/#/category-descriptions)\n- [Broadcom Endpoint Protection Manager Log Format](https://knowledge.broadcom.com/external/article/155205/external-logging-settings-and-log-event.html)\n- [SonicWall SonicOS Log Events Documentation](https://www.sonicwall.com/techdocs/pdf/sonicos-6-5-4-log-events-reference-guide.pdf)\n- [WatchGuard Fireware OS Log Format](https://www.watchguard.com/help/docs/fireware/12/en-US/log_catalog/12_11_Log-Catalog.pdf)\n- [Sophos Firewall Log Documentation](https://docs.sophos.com/nsg/sophos-firewall/19.5/PDF/SF-syslog-guide-19.5.pdf)\n- [Sophos Central Admin Events](https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/LogsReports/Logs/Events/EventTypes/index.html#runtime-detections)\n- [Apache Custom Log Format](https://httpd.apache.org/docs/2.4/mod/mod_log_config.html)\n- [IIS Log File Format](https://learn.microsoft.com/en-us/previous-versions/iis/6.0-sdk/ms525807(v=vs.90))\n- [NGINX Access Log Format](https://nginx.org/en/docs/http/ngx_http_log_module.html#access_log)\n\n### Blogs\n - [The DFIR Report](https://thedfirreport.com/) - Detailed and thorough analysis of real intrusions.\n - [Bad Sector Labs](https://blog.badsectorlabs.com/) - Good catch all aggregator.\n - [This Week In 4n6](https://thisweekin4n6.com/) - Good catch all aggregator focused a lot on dfir.\n - [SOC Investigation](https://www.socinvestigation.com/) - SOC related articles.\n - [Elastic Security Labs](https://www.elastic.co/security-labs) - Good collection of malware analysis blogposts.\n - [Dark Reading](https://www.darkreading.com/) - Cyber security news.\n - [Bleeping Computer](https://www.bleepingcomputer.com/) - Cyber security news.\n - [The Hacker News](https://thehackernews.com/) - Cyber security news.\n\n### Good Reads\n - [A Tour Inside a SOC Analyst Mind | Ali Alwashali](https://hackdefendlabs.com/analysis/A-Tour-Inside-a-SOC-Analyst-Mind/)\n - [Anton’s Alert Fatigue: The Study](https://medium.com/anton-on-security/antons-alert-fatigue-the-study-0ac0e6f5621c)\n\n### Newsletters\n- [Last Week in Security (LWiS)](https://subscribe.badsectorlabs.com/subscription/form)\n- [CyberWeekly](https://cyberweekly.substack.com/)\n- [tl;dr sec](https://tldrsec.com/)\n\n### Podcasts\n- [Darknet Diaries](https://darknetdiaries.com/) - True stories from the dark side of the Internet.\n\n### Books\n- [Blue Team Handbook: SOC, SIEM, and Threat Hunting](https://www.amazon.com/Blue-Team-Handbook-Condensed-Operations/dp/1091493898)\n- [Blue Team Handbook: Incident Response Edition](https://www.amazon.com/Blue-Team-Handbook-condensed-Responder/dp/1500734756)\n- [Effective Threat Investigation for SOC Analysts: The ultimate guide to examining various threats and attacker techniques using security logs](https://www.packtpub.com/en-gr/product/effective-threat-investigation-for-soc-analysts-9781837634781)\n- [BTFM: Blue Team Field Manual](https://www.amazon.com/Blue-Team-Field-Manual-BTFM/dp/154101636X)\n\n### Training and Certifications\n- [Blue Team Labs Online](https://blueteamlabs.online/) - A gamified platform for defenders to practice their skills in security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting.\n- [The DFIR Labs](https://thedfirreport.com/services/dfir-labs/) - Cloud-based DFIR Labs offer a hands-on learning experience, using real data from real intrusions. \n- [LetsDefend SOC Analyst Path](https://app.letsdefend.io/path/soc-analyst-learning-path)\n- [TCM Security Security Operations (SOC) 101](https://academy.tcm-sec.com/p/security-operations-soc-101)\n- [TCM Security Security SOC Level 1 Live Training](https://certifications.tcm-sec.com/product/soc-level-1-live-training/)\n- [Security Blue Team L1](https://www.securityblue.team/certifications/blue-team-level-1)\n- [Security Blue Team L2](https://www.securityblue.team/certifications/blue-team-level-2)\n- [HackTheBox Academy SOC Analyst](https://academy.hackthebox.com/path/preview/soc-analyst)\n- [TryHackMe SOC Simulator](https://tryhackme.com/r/soc-sim/?ref=nav)\n- [TryHackMe SOC Level 1 Training Path](https://tryhackme.com/r/path/outline/soclevel1)\n- [TryHackMe SOC Level 2 Training Path](https://tryhackme.com/r/path/outline/soclevel2)\n- [Constructing Defense](https://course.constructingdefense.com/constructing-defense)\n- [CyberDefenders CCD](https://cyberdefenders.org/blue-team-training/courses/certified-cyberdefender-certification/)\n- [SANS SEC401: Security Essentials - Network, Endpoint, and Cloud](https://www.sans.org/cyber-security-courses/security-essentials-network-endpoint-cloud/)\n- [SANS SEC450: Blue Team Fundamentals: Security Operations and Analysis](https://www.sans.org/cyber-security-courses/blue-team-fundamentals-security-operations-analysis/)\n- [SANS SEC504: Hacker Tools, Techniques, and Incident Handling](https://www.sans.org/cyber-security-courses/hacker-techniques-incident-handling/)\n- [OffSec SOC-200: Foundational Security Operations and Defensive Analysis](https://www.offsec.com/courses/soc-200/)\n- [TCM Security Practical SOC Analyst Associate](https://certifications.tcm-sec.com/psaa/)\n- [CompTIA CySA+](https://www.comptia.org/certifications/cybersecurity-analyst)\n- [CompTIA Security+](https://www.comptia.org/certifications/security)\n- [EC-Council Certified SOC Analyst](https://iclass.eccouncil.org/our-courses/certified-soc-analyst-csa)\n- [EC-Council Certified Incident Handler](https://iclass.eccouncil.org/our-courses/certified-incident-handler-ecih/)\n\n### Twitter/X\n- [TheDFIRReport](https://x.com/TheDFIRReport)\n- [Unit42](https://x.com/Unit42_Intel)\n- [malwrhunterteam](https://x.com/malwrhunterteam)\n- [abuse_ch](https://x.com/abuse_ch)\n- [elasticseclabs](https://x.com/elasticseclabs)\n- [nextronresearch](https://x.com/nextronresearch)\n- [TheHackersNews](https://x.com/TheHackersNews)\n- [BleepinComputer](https://x.com/BleepinComputer)\n- [DarkWebInformer](https://x.com/DarkWebInformer)\n- [malwrhunterteam](https://x.com/malwrhunterteam)\n- [vxunderground](https://x.com/vxunderground)\n- [Cryptolaemus1](https://x.com/Cryptolaemus1)\n- [SOC List](https://x.com/i/lists/1903760692731056442)\n\n### Interview Questions\n- [SOC Interview Questions | LetsDefend](https://github.com/LetsDefend/SOC-Interview-Questions)\n- [Interview Questions | socinvestigation.com](https://www.socinvestigation.com/soc-interview-questions-and-answers-cyber-security-analyst/)\n- [SOC Interview Questions | siemxpert.com](https://www.siemxpert.com/blog/soc-analyst-interview-question/)\n\n### Tools\n\n#### Sandboxes\n- [VirusTotal](https://www.virustotal.com/gui/home/search) - Analyze suspicious files, domains, IPs and URLs to detect malware and other breaches.\n- [Hybrid Analysis](https://www.hybrid-analysis.com/) - Free malware analysis service for the community that detects and analyzes unknown threats.\n- [AnyRun](https://app.any.run/) - Interactive malware analysis sandbox.\n- [Triage | Recorded Future ](https://tria.ge/s) -  Malware analysis sandbox.\n- [JOE Sandbox Cloud Basic](https://www.joesandbox.com/#windows) -  Malware analysis sandbox.\n- [Threat Zone](https://app.threat.zone/scan) - Holistic malware analysis platform - interactive sandbox, static analyzer, emulation, URL Analyzer.\n- [Filescan.io](https://www.filescan.io/scan) - Insightful Malware Analysis Powered by Emulation.\n- [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/) - Engine powered by ReversingLabs Titanium Platform\n- [DOGGuard](https://app.docguard.io/) - Analyze files, Hashes and URLs.\n- [Kaspersky Threat Intelligence Portal](https://opentip.kaspersky.com/?tab=upload) - Kaspersky file analysis.\n\n#### IOC Lookups\n- [VirusTotal | IP, Domain, URL, Hash](https://www.virustotal.com/#/home/search)\n- [Cisco Talos Intelligence | IP, URL, Domain, Hash](https://talosintelligence.com/)\n- [AbuseIPDB | IP, Subnet, Domain](https://www.abuseipdb.com/)\n- [SpamHaus | IP, Domain, ASN, SBL, Email, Hash](https://check.spamhaus.org/)\n- [MalwareBazaar | Hash](https://bazaar.abuse.ch/browse/)\n- [URLHaus | Domain, URL, Hash](https://urlhaus.abuse.ch/browse/)\n- [IBM X-Force Exchange | IP, URL, Hash](https://exchange.xforce.ibmcloud.com/)\n- [ThreatFox IOC Database | IP, Domain, URL, Hash](https://threatfox.abuse.ch/browse/)\n- [GreyNoise | IP](https://viz.greynoise.io/)\n- [Pulsedive | IP, URL, Domain](https://pulsedive.com/analyze/)\n- [threatbook | IP, Domain](https://threatbook.io/)\n- [FortiGuard Labs | IP, Domain, URL](https://www.fortiguard.com/search)\n- [Spamhaus IP Reputation | IP](https://www.spamhaus.org/ip-reputation/)\n- [Spamhaus Domain Reputation | Domain](https://www.spamhaus.org/domain-reputation/)\n- [Palo Alto URL | URL](https://urlfiltering.paloaltonetworks.com/query/)\n- [DOGGuard | URL, Hash](https://app.docguard.io/)\n- [AlienVault | IP, Domain, URL, Hash, FilePath, Email](https://otx.alienvault.com)\n- [Kaspersky Threat Intelligence Portal | Hash, IP, Domain, URL](https://opentip.kaspersky.com/?tab=lookup)\n- [Tor Metrics - ExoneraTor | IP (Tor network)](https://metrics.torproject.org/exonerator.html)\n- [Tor Metrics - Relay Search | IP (Tor relay)](https://metrics.torproject.org/rs.html#search)\n\n#### Emails\n- [MXToolbox Emails| DMARC, SPF, DKIM, Header Analyzer](https://mxtoolbox.com/NetworkTools.aspx?tab=Email)\n\n#### Multifunctional LookUp Services\n- [IPVoid](https://www.ipvoid.com/)\n- [MXToolbox](https://mxtoolbox.com/)\n- [HackerTarget](https://hackertarget.com/)\n- [ViewDNS](https://viewdns.info/)\n- [IPduh](https://ipduh.com/)\n- [SPUR](https://spur.us)\n\n#### Fingerprinting\n - [Censys](https://search.censys.io/)\n - [Shodan](https://www.shodan.io/)\n - [ZoomEye](https://www.zoomeye.ai/)\n - [Onyphe](https://search.onyphe.io/)\n - [FOFA](https://en.fofa.info/)\n\n#### Network Scanning\n - [MXToolbox Network Tools](https://mxtoolbox.com/NetworkTools.aspx?tab=Network)\n - [MXToolbox TCP Port Scan](https://mxtoolbox.com/TCPLookup.aspx)\n - [MXToolbox Ping](https://mxtoolbox.com/PingLookup.aspx)\n - [MXToolbox Traceroute](https://mxtoolbox.com/TraceRouteLookup.aspx)\n - [HackerTarget](https://hackertarget.com/)\n - [HackerTarget Nmap Scanner](https://hackertarget.com/nmap-online-port-scanner/)\n - [HackerTarget TCP Port Scan](https://hackertarget.com/tcp-port-scan/)\n - [HackerTarget UDP Port Scan](https://hackertarget.com/udp-port-scan/)\n - [HackerTarget Ping](https://hackertarget.com/test-ping/)\n - [HackerTarget Traceroute](https://hackertarget.com/online-traceroute/)\n - [DNSChecker Port Scanner](https://dnschecker.org/port-scanner.php)\n\n#### SSL/TLS\n- [HackerTarget SSL Check](https://hackertarget.com/ssl-check/)\n\n#### Website Scan\n - [HackerTarget Whatweb/Wappalyzer Scan](https://hackertarget.com/whatweb-scan/) - Website technology analyzer.\n - [HackerTarget Dump Links](https://hackertarget.com/extract-links/) - Dump links from a website.\n\n#### CMS Scan\n- [HackerTarget Wordpress Scan](https://hackertarget.com/wordpress-security-scan/)\n- [HackerTarget Joomla Scan](https://hackertarget.com/joomla-security-scan/)\n- [HackerTarget Drupal Scan](https://hackertarget.com/drupal-security-scan/)\n\n#### URL\n- [VirusTotal](https://www.virustotal.com/#/home/search) - Scans provided URLs.\n- [urlscan.io](https://urlscan.io/) - Page source code, requests analysis.\n- [Cloudflare Radar URL Scan](https://radar.cloudflare.com/scan) - Gives you information about cookies, technology used, SSL certificates, headers and dns records and other.\n- [URLVoid](https://www.urlvoid.com/) - Reputation check.\n- [URLQuery](https://urlquery.net/search) -  Very nice analysis of the the scanned URL along with reputation check.\n- [CyberGordon](https://cybergordon.com/) - Multiple engines scan.\n- [Tiny Scan](https://www.tiny-scan.com/) - Gives you information about cookies, technology used, SSL certificates, headers and dns records and other.\n- [CheckPhish](https://checkphish.bolster.ai/) - Check if URL is phishing.\n- [PhishTank](https://phishtank.org/) - Check if URL is phishing.\n- [HTTPStatus.io](https://httpstatus.io/) - Check URLs.\n- [Redirect Checker](https://redirect-checker.net/) - Shows redirects.\n\n#### DNS\n - [MXToolbox DNS Tools](https://mxtoolbox.com/NetworkTools.aspx?tab=DNS) - MXToolbox DNS tools.\n - [DNSChecker DNS Tools](https://dnschecker.org/all-tools.php#dnsTool) - DNSChecker DNS Tools.\n - [IPVoid Dig Lookup](https://www.ipvoid.com/dig-dns-lookup/) - Dig DNS Lookup.\n - [DNS Dumpster](https://dnsdumpster.com/) - DNS records.\n - [DNS History](https://dnshistory.org/) - Historical DNS records.\n\n#### MAC\n- [macaddress.io](https://macaddress.io) - Information about manufacturers.\n- [macvendors.com](https://macvendors.com) - Information about manufacturers.\n- [DNS Checker MAC Lookup](https://dnschecker.org/mac-lookup.php) - Information about manufacturers.\n\n#### ASN\n - [ASN LookUp](https://asnlookup.com/)\n - [HackerTarget ASN Lookup](https://hackertarget.com/as-ip-lookup/)\n - [MXToolbox ASN Lookup](https://mxtoolbox.com/asn.aspx)\n\n#### Browser Extension\n- [CRXaminer](https://crxaminer.tech/) - Chrome extension analyzer.\n\n#### User Agent\n- [WhatMyUserAgent](https://whatmyuseragent.com/)\n- [WhatIsMyBrowser](https://explore.whatismybrowser.com/useragents/parse/)\n\n#### USB and PCI\n - [DeviceHunt](https://devicehunt.com/) - Find your device \u0026 driver from a massive database of PCI and USB devices.\n\n#### EXE Lookup\n- [XCyclopedia](https://strontic.github.io/xcyclopedia/index) - Look up information about known exe files - hashes, known paths, metadata, other.\n\n#### Certificate\n- [crt.sh](https://crt.sh/) - Certificate Search\n\n#### Hash\n - [Hash Calculator](https://md5calc.com/hash) - Calculator for hashes.\n - [Hash Crack](https://crackstation.net/) - Cracking hashes online.\n\n#### Misc Tools\n - [WayBack Machine](https://web.archive.org/) - Historical search of pages.\n - [RedHunt Labs Online Paste Tools Lookup](https://redhuntlabs.com/online-ide-search/) - Lookup keywords on online paste sites like pastebin.\n - [de4js](https://lelinhtinh.github.io/de4js/) - JavaScript Deobfuscator and Unpacker.\n - [deobfuscate.relative.im](https://deobfuscate.relative.im/) - JavaScript Deobfuscator.\n - [A-Packets PCAP Analyzer](https://apackets.com/) - PCAP analyzer from A-Packets.\n - [URLEncoder](https://www.urlencoder.org/) - URL encoder and decoder.\n - [explainshell.com](https://explainshell.com/) - Write down a command-line to see the help text that matches each argument\n - [Crontab Guru](https://crontab.guru) - The quick and simple editor for cron schedule expressions.\n - [MXToolbox Subnet Calculator](https://mxtoolbox.com/subnetcalculator.aspx) -  Enter a subnet range (CIDR) and see IP address information about that range.\n - [EpochConverter](https://www.epochconverter.com/) - Epoch \u0026 Unix Timestamp Conversion Tools.\n - [10 minute mail](https://10minutemail.com/) - Can be used for registrations.\n\n#### Data Manipulation Online Tools\n - [Regex101](https://regex101.com/) - Regex testing.\n - [Regexr](https://regexr.com/) - Regex testing.\n - [CyberChef](https://gchq.github.io/CyberChef/) - Multiple data manipulation tools, decoders, decryptors.\n - [JSON Formatter](https://jsonformatter.curiousconcept.com/#) - JSON Beautifier.\n - [JSONCrack](https://jsoncrack.com/editor) - JSON, YML, CSV, XML Editor.\n - [Text Mechanic](https://textmechanic.com/) - Text manipulation  (Remove duplicates, prefix, suffix, word count etc.).\n - [Text Fixer](https://www.textfixer.com/) - Text manipulation (Remove duplicates, prefix, suffix, word count etc.).\n - [Free Formatter](https://www.freeformatter.com/xml-formatter.html) - Formatter for XML, JSON, HTML.\n - [Diff Checker](https://www.diffchecker.com/) - Diff comparison.\n - [ChatGPT](https://chatgpt.com/) - Can be used to transform data.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fst0pp3r%2Fawesome-soc-analyst","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fst0pp3r%2Fawesome-soc-analyst","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fst0pp3r%2Fawesome-soc-analyst/lists"}