Instagram story viewer> @alert2action> Posts
70
followers
140
following
🚨 CSOC Analyst for NHS UK
🔍 Real-world SOC investigations
🛡️ Detection • Threat Hunting • Incident Response
POSTS STORIES REELS TAGGED
Download All
I’d first understand what triggered the alert and validate whether it’s actually malicious.

I’d look at the affected asset, user, business impact, scope and whether the activity is still happening.

If there’s evidence of an active or high-impact incident, I’d escalate immediately according to the incident-response process.

I’d clearly communicate what we know, what we don’t know and what we’re doing about it.

Interview tip:
Alert severity ≠ incident severity. Context matters.

#socanalyst #cybersecurity #cybersecurityinterview #cyber #tech taken in London, England by @alert2action
1
13 hours ago
Download
Absolutely not.

I’d look for evidence elsewhere — SIEM, EDR, firewall, authentication systems, cloud logs and other endpoints.

I’d also investigate when the logs were deleted and which account performed the action.

Interview tip:
Attackers can delete evidence from one system, but they can’t necessarily erase every trace of their activity.

#socanalyst #cybersecurity #cybersecurityinterview #cyber #tech taken in Great Orme by @alert2action
0
2 days ago
Download
I wouldn’t approve the payment based on the email alone.

I’d verify the request using an independent communication method and check whether the CEO’s account has been compromised.

I’d investigate sign-ins, mailbox activity and any suspicious forwarding rules.

Interview tip:
When money is involved, urgency should make you more cautious, not less.

#socanalyst #cybersecurity #cybersecurityinterview #cyber #tech taken in London, England by @alert2action
3
4 days ago
Download
**Answer:**

Very concerned, but I’d still validate it.

I’d identify who ran PowerShell, what command was executed and whether it was authorised administrative activity.

I’d then investigate the account and look for other suspicious activity.

Because it’s a Domain Controller, I’d escalate quickly if the activity isn’t legitimate.

**Interview tip:**
Same activity + different asset = **different level of risk**.

#socanalyst #cybersecurity #cyber #tech #networksecurity taken in London, England by @alert2action
1
4 days ago
Download
I’d first establish whether the activity was legitimate.

I’d check the user, device, IP, files accessed and time period.

I’d then look for signs of account compromise or data exfiltration.

If the activity is unauthorised, I’d contain the account and determine exactly what data was accessed.

Interview tip:
The unusual part isn’t just the number of files — it’s the change from normal behaviour.

#socanalyst #cybersecurity #cybersecurityinterview #cyber #tech taken in London, England by @alert2action
2
6 days ago
Download
I’d immediately find out who created the account and whether it was authorised.

I’d check the account’s creation logs, source IP and activity afterwards.

If there’s no legitimate explanation, I’d treat it as potential persistence and investigate the systems the account accessed.

Interview tip:
An unexpected privileged account can be a major persistence indicator.

#socanalyst #cybersecurity #cybersecurityinterview #blueteam💙 #cyber taken in London, England by @alert2action
1
11 days ago
Download
I’d take the report seriously and first determine whether there is an active remote session.

I’d check EDR, remote-access tools, logged-in users and network connections.

If unauthorised remote access is confirmed, I’d isolate the endpoint if appropriate and preserve the evidence.

Then I’d investigate how the attacker gained access.

Interview tip:
When an attack may still be active, containment becomes time-critical.

#socanalyst #cybersecurity #cybersecurityinterview #cyber #tech taken in London, England by @alert2action
2
12 days ago
Download
I’d treat it as suspicious, but I wouldn’t immediately accuse the employee.

I’d compare the activity with their normal behaviour and check exactly what data was accessed and where it went.

I’d preserve the evidence and escalate through the appropriate process.

Interview tip:
A SOC analyst should follow evidence, not assumptions - even when the behaviour looks suspicious.

#socanalyst #cybersecurity #blueteam💙 #cybersecurityinterview #cyber taken in London, England by @alert2action
4
13 days ago
Download
I'd treat it as a potential active malware incident. 
I'd isolate the endpoint to prevent further spread and preserve the evidence. 
Then I'd investigate what executed from the USB and whether any other machines were affected. 

Interview tip: when something is actively spreading, containment comes first. 

#socanalyst #cybersecurity #blueteam💙 #cybersecurityinterview #cyber taken in London, England by @alert2action
0
14 days ago
Download
I'd investigate the authentication logs and session details. 
I'd look for suspicious MFA activity, Token/session abuse, unusual devices and authentication methods. 
I'd also check whether the attacker obtained an existing session or token rather than simply bypassing MFA. 

Interview tip: 
MFA succeeded doesn't automatically mean the user authenticated. 

#socanalyst #cybersecurity #blueteam💙 #cybersecurityinterview #cyber by @alert2action
2
15 days ago
Download
I’d treat this as a potential account compromise.

I’d check the sign-in logs, source IP, device and what happened immediately after MFA approval.

I’d revoke the user’s sessions, reset credentials and investigate for suspicious activity according to our incident process.

I’d also check whether other users received similar MFA prompts.

Interview tip:
Repeated MFA prompts can be a sign that someone already has the user’s password.

#socanalyst #cybersecurity #blueteam💙 #cybersecurityinterview #cyber taken in London, England by @alert2action
1
18 days ago
Download
I wouldn’t simply work through them from top to bottom.

I’d prioritise based on severity, affected assets, business impact and whether there’s evidence of an active attack.

I’d also look for alerts that are connected — 50 alerts might actually be one incident.

Then I’d investigate the highest-risk activity first and escalate anything that needs immediate attention.

Interview tip:
A good SOC analyst doesn’t just process alerts. They prioritise risk.

#socanalyst #cybersecurity #blueteam💙 #cybersecurityinterview #cyber 

Tags(SOC Analyst Intern, Remote Internship, Cybersecurity, Blue Team, Security Operations Center, SIEM, Threat Detection, Incident Response, Security Monitoring, Alert Investigation, Log Analysis, Wazuh, Splunk, Microsoft Defender, Windows Security, SOC Life, Remote Work, Cybersecurity Career, Cybersecurity Student, Digital Forensics, Network Security, Threat Hunting, Learning Cybersecurity, SOC Workflow, Security Alerts, Blue Team Journey, Cyber Lab, Tech Career, Work From Home, Day in My Life, internship, SOCL1 Analayst, soc analyst, inten life, cybersecurity analyst, cybersecurity) taken in London, England by @alert2action
1
19 days ago
Download
×

Download all media on this page

Photos Videos
back to up