Skip to content

Mitesh2020/30-Days-MyDFIR-SOC-Analyst-Challenge

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

72 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

30 DAYS MYDFIR SOC ANALYST CHALLENGE

Made With Elasticsearch Logstash Kibana Sysmon Mythic osTicket Windows Server Ubuntu Server

forthebadge forthebadge



SUMMARY

1st Week:

  1. Introduction to ELK
  2. How to set up ELK
  3. Ingesting logs such as Sysmon

2nd Week:

  1. Introduction to brute force attacks
  2. How to set up SSH and RDP servers
  3. Create alerts & dashboards

3rd Week:

  1. Introduction to command and control
  2. How to set up your own C2 server (Mythic)
  3. Attack our public servers

4th Week:

  1. Introduction to a ticketing system
  2. How to set up and integrate a ticketing system
  3. Go over how to investigate alerts (high-level)




DAY 1 | HOW TO CREATE A LOGICAL DIAGRAM

  1. Draw.io file

  2. Final Diagram



DAY 2 | ELK STACK INTRODUCTION

  1. Notes
  2. Documentation



DAY 3 | ELASTICSEARCH SETUP TUTORIAL

  1. Notes
  2. Dowload ElasticSearch



DAY 4 | KIBANA SETUP TUTORIAL

  1. Notes
  2. Dowload Kibana



DAY 5 | WINDOWS SERVER 2022 INSTALLATION

  1. Notes



DAY 6 | ELASTIC AGENT AND FLEET SERVER INTRODUCTION

  1. Notes



DAY 7 | ELASTIC AGENT AND FLEET SERVER SETUP TUTORIAL

  1. Notes
  2. If any error encountered, watch this



DAY 8 | WHAT IS SYSMON?

  1. Notes
  2. Sysmon Documentation



DAY 9 | SYSMON SETUP TUTORIAL

  1. Notes



DAY 10 | ELASTICSEARCH INGEST DATA TUTORIAL

  1. Notes



DAY 11 | WHAT IS A BRUTE FORCE ATTACK?

  1. Notes



DAY 12 | UBUNTU SERVER 24.04 INSTALLATION

  1. Notes



DAY 13 | HOW TO INSTALL ELASTIC AGENT ON UBUNTU

  1. Notes
  2. Expected Output



DAY 14 | HOW TO CREATE ALERTS AND DASHBOARD IN KIBANA PART 1

  1. Notes



DAY 15 | REMOTE DESKTOP PROTOCOL INTRODUCTION

  1. Notes



DAY 16 | HOW TO CREATE ALERTS AND DASHBOARD IN KIBANA PART 2

  1. Notes



DAY 17 | HOW TO CREATE ALERTS AND DASHBOARD IN KIBANA PART 3

  1. Notes



DAY 18 | COMMAND AND CONTROL INTRODUCTION

  1. Notes



DAY 19 | HOW TO CREATE AN ATTACK DIAGRAM

  1. Notes
  2. Draw.io file
  3. PDF file



DAY 20 | MYTHIC SERVER SETUP TUTORIAL

  1. Notes



DAY 21 | MYTHIC AGENT SETUP TUTORIAL

  1. Notes
  2. Mythic C2 Profiles
  3. Mythic C2 Agents



DAY 22 | HOW TO CREATE ALERTS AND DASHBOARD IN KIBANA PART 4

  1. Notes



DAY 23 | WHAT IS A TICKETING SYSTEM?

  1. Notes



DAY 24 | OSTICKET SETUP TUTORIAL

  1. Notes



DAY 25 | OSTICKET + ELK INTEGRATION

  1. Notes



DAY 26 | INVESTIGATE SSH BRUTE FORCE ATTACK

  1. Notes



DAY 27 | INVESTIGATE RDP BRUTE FORCE ATTACK

  1. Notes



DAY 28 | INVESTIGATE MYTHIC AGENT

  1. Notes



DAY 29 | ELASTIC DEFEND SETUP TUTORIAL

  1. Notes



DAY 30 | TROUBLESHOOTING

  1. Notes

About

A hands-on, end-to-end cybersecurity SOC analyst training lab designed to simulate real-world scenarios in a safe environment. This 30-day challenge walks through setting up a full SOC infrastructure and investigating common attack patterns using industry tools.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors