William • SOC and Detection Engineering @williamincyber.bsky.social · 2hInstalling Linux is easy. Getting your WiFi adapter to cooperate? That’s where character development begins. If you’ve ever fought with Linux WiFi drivers, you understand this picture. 020
William • SOC and Detection Engineering @williamincyber.bsky.social · 3hA SYN packet doesn't mean a connection succeeded. TCP requires 3 steps: SYN: Client requests. SYN ACK: Server responds. ACK: Connection established. For SOC analysts, incomplete handshakes can indicate scanning, SYN floods, or network failures. Investigate before concluding. 010
William • SOC and Detection Engineering @williamincyber.bsky.social · 3hAn attacker can leave evidence in your logs without triggering a single alert. Why? Your detection rules may not recognize the behavior. A good detection rule turns suspicious patterns into actionable alerts. Collecting logs is not enough. You need to know what to detect. 010
William • SOC and Detection Engineering @williamincyber.bsky.social · 4hMy SOC lab is being built for investigations, not just screenshots of working tools. Clear identity structure matters when authentication activity and security events enter the picture. The OUs were taking shape. Next came the accounts that would use them. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 4hI ran Get-ADOrganizationalUnit again. This time, the output showed Admins. The correction was visible in Active Directory. That is the habit I want to build. Make a change. Verify the actual result. Do not confuse a command running with proof of success. 110
William • SOC and Detection Engineering @williamincyber.bsky.social · 4hThe OU existed, but its name was wrong. That matters when I eventually organize identities and manage Group Policy. I used Rename-ADObject in PowerShell to correct the name. But running the command was only half the work. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 4hOne extra character was enough to make my Active Directory structure look wrong. Part 18 of rebuilding my SOC home lab. While verifying the OUs in corp.local, I noticed the administrative OU was named -Admins. Not Admins. A small mistake worth correcting. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 5hSOC lesson: Investigate behavior, not just application names. Check parent processes, unexpected network connections, and deviations from normal activity. Trust is not evidence of safety. SOC CASE FILES | 01 3CX Supply Chain Attack, 2023. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 5hHere is the SOC investigation challenge. What happens when malicious activity comes from an application your organization already trusts? A legitimate process name does not prove legitimate behavior. The execution chain and surrounding activity matter. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 5hA 3CX employee installed a compromised X_TRADER application. Attackers stole corporate credentials, accessed the company environment, and eventually compromised its software build systems. Trusted software became a malware delivery mechanism. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 5hA trusted software update became the attack. In 2023, researchers discovered malicious code inside the legitimate 3CX desktop app. But the investigation revealed something unexpected. The compromise had started with another software installer. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 7hI don't need to pretend my home lab is a real SOC to demonstrate what I'm learning. I'd rather show what I built, explain what I investigated and be honest about my limitations. There's a difference between claiming experience and demonstrating readiness. That's the standard I'm working toward. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 7hMy goal is to prepare for those challenges before getting my first SOC role. Investigate suspicious activity. Validate evidence. Question assumptions. Document findings. Explain conclusions. These are habits I can start developing now, even without production SOC experience. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 7hIn my home lab, I can choose the scenario, generate activity and study the evidence. But a real SOC analyst may face unfamiliar systems, incomplete telemetry and alerts with no obvious explanation. That's why I don't confuse controlled practice with production experience. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 7hI can build a home lab, simulate attacks and investigate the evidence. But I'm not calling that professional SOC experience. In my lab, I control the environment. In a real SOC, the environment, business context and consequences are very different. That distinction matters. 130
William • SOC and Detection Engineering @williamincyber.bsky.social · 7hI agree. I’ve started publishing longer technical case studies on Medium because some investigations need more room for the evidence, reasoning, and limitations. It is also teaching me how to explain my work more clearly. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 7hCyber Awareness Day 11 Five events can look harmless until you put them in order. A login. PowerShell execution. A downloaded script. A scheduled task. An outbound connection. The sequence raises questions. The evidence must establish whether they are connected. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 21hA padlock in your browser does not automatically mean a website is trustworthy. So how does your browser verify its identity? PKI manages the certificates and trust relationships behind secure connections. Encryption protects data. PKI helps establish who you trust. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026I am deliberately building the infrastructure before jumping into alerts. Otherwise, I could end up investigating logs without understanding where they came from. The domain was verified. Next, I needed a working Windows 11 VM inside Proxmox. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026That relationship matters for a SOC lab. The Domain Controller provides identity services. The endpoint generates activity. Together, they can produce authentication and security events worth investigating. But first, the systems need to be built and connected correctly. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026I moved to the next build stage. Preparing Windows 11 installation media for Proxmox. I selected the x64 ISO from Microsoft's official download page. The goal was not simply another VM. It was a client that could eventually depend on DC01. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026A Domain Controller without a client can only tell me part of the story. Part 17 of rebuilding my SOC home lab. DC01 was running and corp.local was verified. But I still needed a Windows endpoint that could eventually join the domain and generate activity to investigate. 110
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Cyber Awareness Day 10 Base64 caught my attention. Decoding it was only the beginning. An encoded PowerShell command is not automatically malicious. I want to know what it does, who executed it and what happened afterward. Decode the content. Investigate the behavior. 020
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026One thing I'm discovering while building my cybersecurity career is that progress isn't always something worth posting. Sometimes it's understanding something today that confused me last week. And I'm learning to appreciate that kind of growth too. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026So I'm learning to bring my attention back to three things. Myself. My craft. My progress. Not because other people's achievements don't matter, but because their career timeline doesn't determine mine. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026But I'm learning something. Watching someone else's progress doesn't improve my own skills. That same energy could go into understanding logs, practicing investigations, or finally figuring out something I struggled with yesterday. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026I'm starting to realize how much energy I could lose comparing my cybersecurity journey to someone else's progress. Someone lands a SOC role. Someone earns another certification. And suddenly, it's easy to question whether I'm doing enough. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Being an adult is realizing that having absolutely nothing planned for the weekend is sometimes the best plan. No meetings. No deadlines. No alarms. Just peace and the freedom to do absolutely nothing. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026A quiet SOC dashboard doesn't always mean your environment is secure. Sometimes the problem is missing logs. Before trusting a dashboard with zero alerts, verify that your log sources are actually sending events. You can't detect what you can't see. 010
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Thank you, Ryan. I’m taking that seriously. Automation can surface patterns, but I still want to verify the evidence manually, document what I find, and understand where the logs may be incomplete or misleading. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Thank you so much let me check the article out 😌 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Past 1 AM and I’m still awake. Laptop on one side. Tehran playing on TV. Espionage, intelligence operations, hacking, undercover missions. I’m supposed to be relaxing, but I’m watching the same things I spend my days learning about. 😂 Some interests never switch off. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Getting stuck doesn't mean you're not cut out for cybersecurity. It means you've reached something you don't understand yet. Investigate. Question your assumptions. Follow the evidence. Tools help you find information. Your thinking makes you a better analyst. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026One thing my SOC home labs are teaching me is that finding suspicious activity isn't enough. You need to understand what happened, establish what's normal, and support your conclusions with evidence. Otherwise, you're just looking at logs. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Imagine investigating 50 failed login attempts. Finding those failures is easy. But were they from the same IP? Was one account targeted? Did any login eventually succeed? Those questions turn log searching into an actual security investigation. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 10/10/2026Everyone talks about learning Splunk, Wireshark, and SIEM tools. But nobody prepares you for the frustration of SOC investigations. You can spend hours looking through logs without finding a clear answer. That's when your mindset gets tested. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026A successful deployment tells me an operation completed. Verification tells me what I can depend on. That difference matters when endpoints, authentication and security telemetry depend on the system. Next, I needed to make the domain useful. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026The output confirmed: Domain: corp.local NetBIOS: CORP DNS root: corp.local PDC Emulator: dc01.corp.local DC01 also held the RID Master and Infrastructure Master roles. The identity foundation was now verifiable. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026That was encouraging, but a sign in screen was not enough. I opened PowerShell and ran: Get-ADDomain I wanted to verify what the promotion had actually created, rather than assume everything worked because the installation had completed. 110
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026The promotion process finished. But I still needed proof that Active Directory was actually there. Part 16 of rebuilding my SOC home lab. After DC01 restarted, the sign in screen showed CORP\Administrator. The domain identity was now visible. 110
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026I will consider that and thanks 010
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026Finish your project with: Suspicious DNS queries Traffic patterns Source details Timeline Evidence Your verdict Explain what supports DNS tunneling and what remains uncertain. You don't need to create malicious traffic. A sample PCAP is enough to start practising. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026Now investigate further. Are the queries sent at regular intervals? Do the subdomains look encoded? How much data might they carry? Could legitimate software explain the pattern? Don't classify every long DNS query as tunneling. Use the surrounding evidence. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026Start looking for patterns. Long subdomains Repeated queries High query frequency Unusual TXT records Random looking strings Large responses Then identify the source host and destination domain. Your challenge is figuring out what makes the traffic unusual. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026DNS queries can carry more than domain lookups. Here's a SOC project you can build around that behavior. 𝗗𝗡𝗦 𝗧𝘂𝗻𝗻𝗲𝗹𝗶𝗻𝗴 𝗜𝗻𝘃𝗲𝘀𝘁𝗶𝗴𝗮𝘁𝗶𝗼𝗻 Get a public DNS tunneling PCAP or sample logs. Open them in Wireshark and compare normal queries with suspicious ones. 100
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026A document can look authentic and still be altered. How do you prove it came from the right sender and has not changed? Digital signatures use cryptography to verify authenticity and integrity. Before trusting a signed file, verify its signature and signer. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026Your public key can be shared with the world. Your private key cannot. It can decrypt protected data or create digital signatures that prove your identity. If an attacker steals it, they may impersonate you. Protect private keys like your digital identity depends on them. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026Imagine locking a message with a key anyone can use, but only the intended recipient can unlock it. That is public key encryption. The public key encrypts the message. The matching private key decrypts it. The key can be public. The message stays private. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026DC01 was moving from a Windows Server I had prepared into the identity authority for the lab. Users, endpoints and authentication would eventually depend on this domain. Next, I needed to verify exactly what the promotion created after the restart. 000
William • SOC and Detection Engineering @williamincyber.bsky.social · 09/10/2026Then came the message I had been working toward: The server would be configured as a Domain Controller and restarted. I confirmed it. PowerShell validated the environment. All tests completed successfully. The new forest installation started. 100