SOC Analyst Case Study β Security Operations Simulation
π‘οΈ SOC Analyst Case Study (Capstone)
π§ Overview
This page brings together all hands-on security engineering labs into a unified SOC (Security Operations Center) simulation workflow.
π SOC Security Labs Dashboard
π₯ Core Security Operations Labs
π‘οΈ SOC Analyst Case Study β Security Operations Simulation
π Objective
This lab simulates a real-world Security Operations Center (SOC) investigation using Microsoft Sentinel and Azure security tools.
π§ Scenario Overview
A suspicious activity alert was triggered in a simulated enterprise environment. The investigation involved:
- Log analysis in Microsoft Sentinel
- Identity verification using Entra ID logs
- Network traffic inspection
- Threat classification and response
π Investigation Steps
1. Alert Detection (Sentinel)
Security alerts were generated based on anomalous login patterns and network behavior.
2. Log Analysis
Investigated:
- Authentication logs
- VM activity logs
- Firewall logs
3. Threat Validation
Confirmed whether activity was:
- False positive
- Insider threat
- External attack attempt
π§± Tools Used
- Microsoft Sentinel (SIEM)
- Microsoft Defender for Cloud
- Azure Firewall
- Entra ID (Azure AD)
- Log Analytics Workspace
β οΈ Findings
- Suspicious login attempts detected
- IP anomaly flagged by Sentinel analytics rules
- Network segmentation prevented lateral movement
π‘οΈ Response Actions
- Account access reviewed and restricted
- Alert escalated to incident severity level
- Firewall rules validated and adjusted
- Logging rules improved for future detection
π Outcome
β Threat contained successfully
β No data exfiltration occurred
β Detection rules improved
β Incident documented for SOC playbook
πΈ Evidence
(Attach screenshots from Sentinel, logs, and firewall rules from your assets/labs folder)