Skip to content

Repository files navigation

🛡️ Cybersecurity Notes

Cybersecurity SOC Blue Team DFIR License

🚀 A Practical Cybersecurity Knowledge Base built while learning Security Operations (SOC), Detection Engineering, DFIR, Splunk, SIEM and Web Security.

"Learn. Practice. Document. Improve."


📖 About

This repository is my personal cybersecurity knowledge base where I document everything I learn while studying and practicing cybersecurity.

Instead of simply completing labs, I break every topic into detailed notes with explanations, screenshots, practical examples, commands, and real-world concepts.

The goal is simple:

  • Build a second brain for cybersecurity.
  • Help beginners learn faster.
  • Track my own cybersecurity journey.
  • Create a practical reference for future SOC and DFIR work.

🎯 Learning Goals

  • Learn Security Operations Center (SOC)
  • Master SIEM Fundamentals
  • Learn Splunk Search Processing Language (SPL)
  • Understand Endpoint Detection & Response (EDR)
  • Study Windows Event Logs
  • Learn Threat Detection
  • Build Blue Team Skills
  • Understand Cyber Kill Chain
  • Learn Malware Analysis
  • Prepare for SOC Analyst interviews

📂 Repository Structure

Cybersecurity-Notes
│
├── Blogs
│   └── SIEM Solution
│
├── TryHackMe
│
│   ├── Burp Suite
│   │      ├── Introduction
│   │      ├── Proxy
│   │      └── Foxy Proxy
│   │
│   ├── Burp Suite Repeater
│   │      └── Introduction
│   │
│   ├── Burp Suite Intruder
│   │      ├── Attack Types
│   │      ├── Payloads
│   │      ├── Positions
│   │      └── Working of Intruder
│   │
│   └── SOC Level 1
│          ├── Cyber Kill Chain
│          ├── Malware for SOC
│          ├── Pyramid of Pain
│          │
│          └── SOC Solution
│                 ├── SIEM
│                 ├── Splunk
│                 ├── SPL Part 1
│                 ├── SPL Part 2
│                 ├── Investigating EDR Alerts
│                 └── Endpoint Detection & Response
│
└── Attachments
    └── Images used in Notes

📚 Topics Covered

🛡️ SOC Level 1

  • Security Operations Center
  • SIEM
  • Splunk
  • Search Processing Language (SPL)
  • Endpoint Detection and Response (EDR)
  • Alert Investigation
  • Threat Detection
  • Log Analysis

☠️ Threat Detection

  • Cyber Kill Chain
  • Pyramid of Pain
  • Malware Basics

🌐 Web Security

Burp Suite

  • Proxy
  • Repeater
  • Intruder
  • Attack Types
  • Payload Positions
  • Foxy Proxy Configuration

✍️ Blogs

  • SIEM Solutions

📑 What You'll Find

Each note generally contains:

  • 📖 Beginner-friendly explanations
  • 🧠 Important concepts
  • 📸 Screenshots
  • 🛠️ Practical examples
  • 📌 Commands
  • 💡 Tips
  • 🎯 Interview points
  • 🔍 Real-world observations

🚀 Learning Path

Networking
      ↓
Linux Basics
      ↓
Cyber Security Fundamentals
      ↓
SOC Level 1
      ↓
SIEM
      ↓
Splunk
      ↓
SPL Queries
      ↓
EDR
      ↓
Threat Hunting
      ↓
Incident Response
      ↓
DFIR

💻 Tools Covered

  • Splunk
  • Burp Suite
  • FoxyProxy
  • TryHackMe

More tools will be added as my learning journey continues.


🎯 Who is this Repository For?

✅ Students

✅ Beginners

✅ SOC Analyst Aspirants

✅ Blue Team Learners

✅ TryHackMe Learners

✅ Cybersecurity Enthusiasts


📈 Current Focus

  • SOC Level 1
  • Splunk
  • SIEM
  • SPL Queries
  • Detection Engineering
  • Threat Hunting

📅 Future Topics

  • Windows Event Logs
  • Sysmon
  • Sigma Rules
  • YARA Rules
  • Wireshark
  • Zeek
  • Suricata
  • Elastic Stack
  • Wazuh
  • Microsoft Sentinel
  • Digital Forensics
  • Incident Response
  • Malware Analysis
  • Threat Intelligence
  • Detection Engineering
  • Active Directory
  • Network Security
  • Linux Security
  • Cloud Security
  • AWS Security

🤝 Contributions

Suggestions, improvements, and corrections are always welcome.

If you notice something incorrect or have a better explanation, feel free to open an Issue or submit a Pull Request.


⭐ Support

If these notes helped you, consider giving this repository a ⭐.

It motivates me to continue documenting everything I learn.


👨‍💻 Author

Mohak Agarwal

Computer Engineering Student

Cybersecurity | SOC | DFIR | Blue Team | Detection Engineering


🚀 Learning Cybersecurity One Note at a Time.

Happy Learning!

⭐ Star the repository if you found it useful.