1. What is a SOC used for?
A SOC (Security Operations Center) is a cybersecurity monitoring center.
It is used to:
- Detect cyberattacks in real time
- Analyze security alerts
- Respond to incidents (phishing, malware, intrusion, etc.)
- Monitor system and network logs
- Protect an organization 24/7

In short:
A SOC is the “security control center” of an organization.

2. Lab Objectives
This SOC lab helps you:
- Understand how a real SOC works
- Learn how to analyze security logs
- Detect simulated cyberattacks
- Respond to security incidents
- Use professional cybersecurity tools (SIEM, EDR, SOAR)

3. Tools Used in a SOC Lab

1. SIEM – (e.g. Splunk or Elastic Stack)
Role:
- Collects all logs (PCs, servers, firewalls…)
- Detects suspicious behavior
- Generates security alerts

2. EDR (Endpoint Detection & Response)
Role:
- Monitors computers (endpoints)
- Detects malware and suspicious activity

3. SOAR (e.g. TheHive + Cortex)
Role:
- Automates incident response
- Manages security tickets
- Helps security decision-making

4. Network Analysis (Wireshark)
Role:
- Analyzes network traffic
- Detects suspicious connections

5. Virtual Machines (VirtualBox / VMware)
Role:
- Creates a safe SOC simulation environment
- Allows attack testing without risk

4. SOC Interface (Key Splunk Tabs)

1. Search & Reporting
Use:
- Search logs
- Filter suspicious activity

Example:
- failed login attempts
- malware detection

2. Dashboards
Use:
- Visual display of attacks
- Real-time statistics

Example:
- number of attacks per day
- suspicious IP addresses

3. Alerts
Use:
- View automatic security alerts
Example: brute force detection

4. Data Inputs
Use:
- Add log sources
- PCs, servers, firewalls

5. Settings
Use:
- SIEM configuration
- System and machine connections

5. SOC LAB – Step-by-Step Guide (Click by Click)

STEP 1: Install the Environment

1. Install VirtualBox or VMware
- Download VirtualBox
- Install it (Next → Next → Finish)

2. Create Virtual Machines
You create:
- SOC machine (Splunk server)
- Attacker machine (Kali Linux)
- Victim machine (Windows/Linux)

STEP 2: Install SIEM (Splunk)

1. Download Splunk
- Go to official website
- Install Free/Enterprise version

2. Launch Splunk
- Click: Start Splunk
- Open browser:
```
http://localhost:8000
```

3. Login
- Username: admin
- Password: (set during installation)

STEP 3: Add Log Sources

1. Go to:
Settings → Data Inputs

2. Click:
Add Data

3. Choose:
- Files & Directories (system logs)
- Network logs (if available)

STEP 4: Launch a Simulated Attack
From attacker machine:

Examples:
- Brute force login attack
- Network scanning
- Malware execution test

STEP 5: Detection in SOC

1. Go to Search & Reporting

2. Run query:
```
failed login OR brute force
```

3. Result:
- Suspicious IP detected
- Multiple login attempts

STEP 6: Dashboard Analysis
Go to:
Dashboards

You will see:
- Attack graphs
- Traffic spikes
- Attacking IPs

STEP 7: Create an Alert

1. Go to Search

2. Click:
Save As → Alert

3. Configure:
- Trigger if > 5 failed logins
- Action: notification

STEP 8: Incident Response (SOAR)
In TheHive:

1. Create an incident ticket
- Type: Brute Force Attack

2. Add:
- Attacker IP
- Splunk logs

3. Actions:
- Block IP
- Isolate victim machine

STEP 9: Final Validation
You should confirm:
- Attack detected
- Alert generated
- Incident created
- Response executed

6. Final SOC Lab Result
At the end of the lab, you have:
- Real-time attack detection
- Log analysis in SIEM
- Security alerts triggered
- Incident response executed
- Attack successfully blocked

Simple Summary
SOC = detect + analyze + respond

Tools used:
- SIEM (Splunk)
- SOAR (TheHive/Cortex)
- EDR systems
- Wireshark


 

 

 

 



 

     

      

      
 

      

      

 


 

 

 

       

          

 

Copyright © All rights reserved.

 

     
* Cybersecurity Analyst
* SOC Analyst
* Security Operations Center
* Cloud Security
* DevSecOps
* Information Security
* Cybersecurity Engineer
* Threat Detection
* Incident Response
* SIEM Monitoring

---

# 🛡️ 2. Mots-clés SOC (très importants pour recrutement)

* SOC Analyst Tier 1
* SOC Analyst Tier 2
* Security Monitoring
* Log Analysis
* Security Alerts
* Threat Hunting
* Malware Analysis
* Phishing Detection
* Brute Force Detection
* Incident Investigation
* Security Events
* Blue Team

---

# ☁️ 3. Mots-clés Cloud Security

* Cloud Security Engineer
* AWS Security
* Azure Security
* Cloud Infrastructure Security
* Cloud Threat Detection
* Cloud Monitoring
* Identity and Access Management (IAM)
* Cloud Compliance
* Cloud Security Best Practices

---

# ⚙️ 4. Mots-clés DevSecOps

* DevSecOps Engineer
* Secure CI/CD Pipeline
* Security Automation
* Infrastructure as Code Security
* Docker Security
* Kubernetes Security
* Application Security
* Code Security
* SAST / DAST
* Continuous Security

---

# 🔬 5. Mots-clés techniques (très puissants SEO)

* Splunk
* ELK Stack (Elasticsearch, Logstash, Kibana)
* Microsoft Sentinel
* Wireshark
* Sysmon
* Linux Security
* Windows Security Logs
* Network Security
* Firewall Logs
* IDS / IPS

---

# 🚀 6. Mots-clés “portfolio / recrutement”

👉 Très important pour être trouvé par RH

* Cybersecurity Portfolio
* SOC Analyst Portfolio
* Cybersecurity Projects
* Cybersecurity Labs
* Security Use Cases
* Threat Detection Lab
* Cybersecurity Skills
* Entry Level Cybersecurity
* Junior Cybersecurity Analyst

---

# 📈 7. Mots-clés SEO longue traîne (ULTRA PUISSANT)

👉 Ceux-là font la différence 🔥

* Cybersecurity analyst portfolio website
* SOC analyst projects and labs
* How to detect cyber attacks using SIEM
* Cybersecurity incident response examples
* Cloud security best practices for beginners
* DevSecOps security pipeline example
* SIEM log analysis tutorial
* Threat detection use cases

---

# 🧠 STRATÉGIE SEO (très important)

## 📌 Où mettre ces mots-clés :

* Page d’accueil (titre + description)
* Page “About”
* Page “Labs”
* Titres H1 / H2 / H3
* Meta description
* URL des pages

---

# 🏆 EXEMPLE DE TITRE SEO (à utiliser)

👉
**Cybersecurity Analyst Portfolio | SOC, Cloud Security & DevSecOps Projects**

---

# 🏆 EXEMPLE META DESCRIPTION

👉
**Cybersecurity Analyst portfolio with hands-on labs in SOC monitoring, SIEM, Cloud Security and DevSecOps. Available for hiring.**

---
 

Manager DSI (secteur bancaire)

🎯 Mots-clés principau

# 🏦 🔥 1. Mots-clés Manager DSI (secteur bancaire)

## 🎯 Mots-clés principaux

* IT Manager
* IT Director
* Head of IT
* IT Governance
* Information Systems Management
* Digital Transformation
* IT Strategy
* Enterprise IT

---

## 🏦 Spécifique BANQUE (très puissant)

* Banking IT Systems
* Core Banking Systems
* Financial Information Systems
* Banking Cybersecurity
* Risk Management Banking
* IT Compliance Banking
* Data Protection Banking
* Financial Security

---

## ⚖️ Gouvernance & conformité

* IT Governance Framework
* COBIT
* ITIL
* Risk Assessment
* Business Continuity Plan (BCP)
* Disaster Recovery Plan (DRP)
* Regulatory Compliance

---

## 📊 Management & pilotage

* IT Project Management
* Team Leadership IT
* IT Operations Management
* KPI IT Performance
* IT Service Management (ITSM)
* Strategic IT Planning

---

# 🏥 🛡️ 2. Mots-clés RSSI (hôpital / santé)

## 🎯 Mots-clés principaux

* Chief Information Security Officer (CISO)
* Information Security Manager
* Cybersecurity Governance
* Security Risk Management
* Security Policies

---

## 🏥 Spécifique SANTÉ (très important)

* Healthcare Cybersecurity
* Hospital Information Systems (HIS)
* Patient Data Protection
* Medical Data Security
* Health IT Security
* Electronic Health Records (EHR) Security

---

## 🔐 Sécurité & conformité

* ISO 27001
* NIST Cybersecurity Framework
* GDPR Compliance
* Data Privacy
* Access Control
* Identity Management

---

## 🚨 Gestion des incidents

* Incident Response Management
* Security Operations Management
* Cyber Risk Assessment
* Vulnerability Management
* Threat Intelligence

---

# 🚀 🧠 3. Mots-clés hybrides (TRÈS PUISSANTS 🔥)

👉 Ceux-là font le lien entre ton profil actuel et ton évolution :

* Cybersecurity Leadership
* IT Security Strategy
* Enterprise Security Architecture
* Security Governance
* IT Risk Management
* Digital Security Transformation
* Cloud Security Governance