SOC Raw Log Analysis Field Manual Bundle L1->L3

SOC Raw Log Analysis Field Manual Bundle L1->L3
Digital Product
12Sales

Who this is for:

āœ… L1 analysts who want to understand logs, not just click buttons

āœ… L2 analysts building investigation and correlation skills

āœ… Students preparing for BTL1, CySA+, SC-200, or GCIH

āœ… Blue teamers moving into detection engineering

āœ… Anyone who wants to know what a real SOC investigation looks like

Complete Field Manual v3.0 (88 pages)

  1. Most SOC resources teach you how to use dashboards. This one teaches you what's actually behind them.
  2. 88 pages of real log analysis. No fluff, no theory dumps. Just the stuff you need to actually do the job.
  3. You will know what to do the moment an alert fires. You will read any log format without Googling it. You will catch attacks that the SIEM missed because you understand the raw evidence underneath.

Here is what is inside:

  1. Every log format you will see in the field. Syslog, Windows EVTX, CloudTrail, CEF, W3C.
  2. L1 triage workflow. Exactly what to check in the first 60 seconds, in order, every time.
  3. L2 investigation skills. Log correlation, timeline reconstruction, Pass-the-Hash, Kerberoasting, DCSync and catching ransomware before it encrypts a single file.
  4. L3 threat hunting. Finding attackers who never triggered a single alert.
  5. Production-ready Splunk SPL and KQL queries. Copy, paste, run.
  6. Reference appendices you will actually use. Top 50 Windows Event IDs, SubStatus codes, MITRE ATT&CK mapping, IOC checklist, regex patterns.

This is the manual that turns alert-clickers into real analysts.

-Manjil Katuwal

What are people saying

Documents where good and best !! Malware labs where true gem šŸ’Ž
Anonymous
Jun 2026
I was new to cybersecurity career blue roadmap, Manjil walked me through the flowchart it was good session given up . Tools few channels , network packet.
Richard R
Jun 2026
$8$25