Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

SOC Workbooks and Lookups

Premium room

Discover useful corporate resources to help you structure and simplify L1 alert triage.

easy

45 min

43,626

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Alert triage is a complex process that often requires analysts to gather additional information about affected employees or servers. This room explores workbooks designed to streamline alert triage and explains various lookup methods to quickly retrieve user and system context.

Learning Objectives

  • Familiarise yourself with investigation workbooks
  • Learn where to find and how to use asset inventory in
  • Understand the importance of corporate network diagrams
  • Practice workflow building inside an interactive interface

Prerequisites

  • Complete the L1 Alert Triage and Alert Reporting rooms
  • Have practice with investigating common attack chains
  • Understand the fundamental networking concepts
  • Preferably, be familiar with the concept of playbooks
Answer the questions below

I am ready to start!