← INVESTIGATIONSTANVI KAMDI
CASE 03 · SOC LAB · HACK THE BOX ACADEMY

SOC Incident Response Lab

A structured learning case that changed the way I thought about alerts: the alert is not the conclusion. It is where the analyst’s investigation starts.

SOC OperationsSIEM TriageIncident ResponseMITRE ATT&CKDocumentationHandoff
01

The idea that changed how I looked at SOC work

At one point I was learning the difference between an event, an alert and an incident. It sounds basic, but understanding the difference changed the way I looked at SOC work.

An event is recorded activity. An alert is activity a detection mechanism considers worth attention. An incident is something that has been investigated and determined to require formal response or tracking.

02

Starting with triage

The lab reinforced that an analyst should not jump from “alert fired” to “incident confirmed.” Triage begins with context: the affected host or user, timestamp, detection logic, surrounding activity, severity, and whether there are reasonable benign explanations.

03

Investigation means correlation

One log entry in isolation is rarely the whole story. The workflow pushed me to validate the alert, collect surrounding context, correlate related activity, determine scope and assess what the evidence actually supported.

Alert → Validate → Collect context → Correlate → Determine scope → Assess impact
04

MITRE ATT&CK as a way to describe behaviour

MITRE ATT&CK helped me think about observed behaviour in a structured way. The important part was not attaching technique IDs to make a report look technical; it was using the framework when the observed activity genuinely supported a tactic or technique.

05

When an alert becomes an incident

When investigation supports escalation, the activity needs to be tracked as an incident. That means capturing the title/classification, severity, affected assets or users, evidence, timeline, investigation notes and recommended actions in a way another analyst can understand.

06

Response is a workflow, not a single action

The lab connected the stages into a practical flow:

Identify → Triage → Investigate → Contain / Respond → Document → Handoff / Close

It helped me see why the technical answer and the operational response have to stay connected.

07

Documentation and shift handoff

A SOC analyst’s work is not finished when the technical answer is found. The next analyst needs to know what happened, what evidence was reviewed, what was confirmed, what actions were already taken, what remains unanswered and what should happen next.

That made documentation feel less like paperwork and more like part of the investigation itself.

08

What changed for me

Before I started learning SOC workflows properly, I thought the alert itself was the important part. What I gradually understood is that the alert is really where the analyst’s work starts. The investigation is what gives it meaning.

This is a lab, not professional SOC employment, and I want the portfolio to be clear about that. Its value is showing how my understanding of the workflow developed and how naturally it connects with the evidence-first habits I already had from forensics.