William • SOC and Detection Engineering
banner
williamincyber.bsky.social
William • SOC and Detection Engineering
@williamincyber.bsky.social
ISC2 CC | Building toward Tier 1 SOC and Detection Engineering | Hands-on investigations with Splunk, Wazuh and Sigma | Documenting what I learn
Pinned
I’m building in public toward Tier 1 SOC and Detection Engineering roles.

I share:
Home lab builds
Alert triage and investigations
SIEM, EDR and network telemetry
Detection logic and troubleshooting

No production claims. Just evidence of what I’m learning, testing and building.
Mitigation lowers the risk but never erases it.

You add controls to shrink likelihood or impact. Something always remains.

Reflex: what is left after mitigation has a name: residual risk.
September 17, 2026 at 8:25 AM
SOC Home Lab Series | Part 26

The first time I opened a real packet capture in Wireshark, I tried to understand everything on the screen.

That was a mistake.

There were too many packets, protocols, addresses and conversations happening at once.
September 17, 2026 at 6:48 AM
You’re the only one who knows why you chose cybersecurity.

Remember your reason.

Keep going. 💪🏾❤️
September 17, 2026 at 6:24 AM
Risk transference moves the impact, not the risk itself.

Insurance is the classic move. The event can still happen. Someone else now carries the cost.

Reflex: if a third party absorbs the financial hit, the risk was transferred.
September 16, 2026 at 5:12 PM
Risk acceptance is a decision, not a failure to act.

Someone with authority looked at the risk and chose to live with it, on the record.

Reflex: if the risk is knowingly kept with sign-off, that is acceptance, not negligence.
September 16, 2026 at 3:05 PM
💡 Quick SOC Tip #03

Want to see who is logged into a Linux host right now?

$ who

It shows active users, terminals and login times.

Useful during triage when you need a quick view of current sessions before investigating further.
September 16, 2026 at 10:53 AM
SOC Home Lab Series | Part 25

After looking at process relationships, I wanted more context.

A process running is one thing.

A process making a network connection gives me another question:

Where did it go?
September 16, 2026 at 8:00 AM
A standard and a guideline differ by one word: mandatory.

A standard must be followed. A guideline is recommended best practice you may adapt.

Reflex: if it is required, it is a standard. If it is advisory, it is a guideline.
September 16, 2026 at 7:34 AM
A policy and a procedure are not interchangeable.

A policy is the high-level rule and intent. A procedure is the exact steps that carry it out.

Reflex: the what and why is policy. The how, step by step, is procedure.
September 16, 2026 at 4:36 AM
If I buy another computer for my home lab, I’m not just looking at specs anymore.

I’m looking at how long I can keep upgrading it before the lab outgrows it.

That completely changes what “good hardware” means to me.
September 15, 2026 at 8:30 PM
Two alerts both contain 50 failed logins.

They might represent completely different activity.

One source hammering one account.

One source touching dozens of accounts.

Many sources converging on the same account.

Same failure count.
September 15, 2026 at 6:42 PM
Quick SOC Tip #02

Too many failed SSH logins to count manually?

$ grep -c "Failed password" /var/log/auth.log

This gives you the total failures fast.

Useful for checking volume before digging into users, source IPs and timing.
September 15, 2026 at 5:40 PM
A process name tells you what ran.

The parent process can help explain why.

chrome.exe → powershell.exe deserves a different question than explorer.exe → chrome.exe.

Don't investigate the process alone.

Check what launched it.
September 15, 2026 at 3:43 PM
Out-of-band management keeps control when the network dies.

A separate channel reaches the device even when the production network is down or compromised.

Reflex: if admins still reach the gear during an outage, it is out-of-band.
September 15, 2026 at 3:07 PM
SOC Home Lab Series | Part 24

Event ID 4104 showed me what PowerShell executed.

The next question was:

What happened around that execution?

That pushed me into parent and child process relationships.
September 15, 2026 at 1:57 PM
Journaling protects data integrity through a crash.

The filesystem records the change before making it, so an interrupted write can be rolled back or completed cleanly.

Reflex: if recovery after a crash relies on a record of intended changes, that is journaling.
September 15, 2026 at 12:32 PM
Two alerts arrive together:

A critical malware alert on an isolated test laptop.

A medium severity suspicious sign-in involving a privileged account.

Which one should be investigated first?
September 15, 2026 at 12:18 PM
💡 Quick SOC Tip #01

Want to see who recently logged into a Linux host?

$ last

It shows users, login times and session history.

During triage, unexpected accounts or unusual login times give you a useful place to investigate next.
September 15, 2026 at 11:31 AM
One of the easiest SOC mistakes to make is treating an alert like it’s the evidence.

It isn’t.

An EVENT records what happened.

An ALERT tells you detection logic found something worth your attention.

That distinction changes how you investigate.
September 13, 2026 at 4:51 PM
EDR and antivirus are not the same generation.

Antivirus matches known signatures. EDR watches behaviour, records it, and lets you respond across every endpoint.

Reflex: signature-only is AV. Behaviour plus response and visibility is EDR.
September 13, 2026 at 3:55 PM
A visible SMB share does not mean the files inside are exposed.

A simple Ubuntu lab proved the difference.

TCP 445 and 139 were listening.

Both traced back to smbd.

Next question: what does the service actually expose?
September 13, 2026 at 1:53 PM
Day 19

Four access control models, and the exam lives in the gap between two of them. The whole distinction is one question. Who decides 👇
September 13, 2026 at 7:03 AM
NAC checks the device before it lets it on.

Posture assessment. Patch level, antivirus, config. Fail the check and the device gets quarantined, not connected.

Reflex: if access depends on the health of the endpoint, that is NAC.
September 13, 2026 at 6:25 AM
Some days, progress looks like this.

A laptop. A notebook. A few hours of focused learning.

No big announcement.
No milestone.
No certificate.

Just another day of getting better.

The quiet days count too.

Keep showing up.
September 12, 2026 at 10:00 PM
Windows logs show events. Sysmon helps connect behavior.

Event 1 → Process created
Event 3 → Network connection
Event 11 → File created
Event 13 → Registry modified

Process → Network → File → Registry

Don’t just read events. Follow the activity.
September 12, 2026 at 9:06 PM