<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mohd Kashif | SOC Analyst</title><link>https://www.cyberkashif.com/</link><description>Recent content on Mohd Kashif | SOC Analyst</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 27 Jul 2026 10:00:10 +0530</lastBuildDate><atom:link href="https://www.cyberkashif.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Architecture for SOC Analysts: A Complete Guide to Detection &amp; Investigation - Part 11</title><link>https://www.cyberkashif.com/posts/windows-architecture-soc-analysts-detection-guide/</link><pubDate>Mon, 27 Jul 2026 10:00:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/windows-architecture-soc-analysts-detection-guide/</guid><description>&lt;h1 id="windows-architecture-overview"&gt;
 Windows Architecture Overview
 &lt;a class="heading-link" href="#windows-architecture-overview"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;p&gt;Windows architecture defines the foundational structure of the operating system, encompassing how processes run, how memory is managed, how users authenticate, and how security is enforced. For SOC analysts, this architecture represents the primary battlefield where attacks occur and must be detected.&lt;/p&gt;
&lt;h2 id="user-mode-vs-kernel-mode"&gt;
 User Mode vs. Kernel Mode
 &lt;a class="heading-link" href="#user-mode-vs-kernel-mode"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="user-mode"&gt;
 User Mode
 &lt;a class="heading-link" href="#user-mode"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;User mode runs applications such as Chrome, Microsoft Word, and other user processes, along with some system services. Processes operating in this mode face significant restrictions: they cannot directly access hardware and cannot modify the kernel. From a SOC perspective, user mode is where most malware initially executes—phishing emails lead to malicious Word documents, which then launch PowerShell, ultimately enabling malware execution.&lt;/p&gt;</description></item><item><title>About</title><link>https://www.cyberkashif.com/about/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://www.cyberkashif.com/about/</guid><description>&lt;h2 id="hi-im-mohd-kashif-"&gt;
 Hi, I&amp;rsquo;m Mohd Kashif 👋
 &lt;a class="heading-link" href="#hi-im-mohd-kashif-"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;I&amp;rsquo;m an aspiring &lt;strong&gt;SOC Analyst (Level 1)&lt;/strong&gt; based in Lucknow, Uttar Pradesh, currently building my path into cybersecurity through hands-on learning, certifications, and real internship experience.&lt;/p&gt;
&lt;p&gt;I hold a &lt;strong&gt;Google Cybersecurity Professional Certificate&lt;/strong&gt; and completed a 6-month internship at Codevirus Security Pvt. Ltd., where I worked on security monitoring, incident documentation, and network/software troubleshooting. I&amp;rsquo;m currently pursuing &lt;strong&gt;CompTIA Security+&lt;/strong&gt; and the &lt;strong&gt;TryHackMe SOC Level 1&lt;/strong&gt; practical certification to sharpen my skills in log analysis, SIEM investigation, and incident triage.&lt;/p&gt;</description></item><item><title>Contact</title><link>https://www.cyberkashif.com/contact/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://www.cyberkashif.com/contact/</guid><description>&lt;p&gt;I&amp;rsquo;m always open to conversations about SOC roles, cybersecurity, or feedback on what I&amp;rsquo;m building here.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Email:&lt;/strong&gt; &lt;a href="mailto:work.kashif7@gmail.com" &gt;work.kashif7@gmail.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LinkedIn:&lt;/strong&gt; &lt;a href="https://linkedin.com/in/cyberkashif" class="external-link" target="_blank" rel="noopener"&gt;linkedin.com/in/cyberkashif&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Location:&lt;/strong&gt; Lucknow, Uttar Pradesh, India&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Feel free to drop a message — I usually respond within a day or two.&lt;/p&gt;</description></item><item><title>Hire Me</title><link>https://www.cyberkashif.com/hire-me/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://www.cyberkashif.com/hire-me/</guid><description>&lt;h2 id="looking-for-a-level-1-soc-analyst"&gt;
 Looking for a Level 1 SOC Analyst
 &lt;a class="heading-link" href="#looking-for-a-level-1-soc-analyst"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;I&amp;rsquo;m actively looking for opportunities as a &lt;strong&gt;Junior / L1 SOC Analyst&lt;/strong&gt;, ideally in threat monitoring, alert triage, or incident response.&lt;/p&gt;
&lt;h3 id="why-hire-me"&gt;
 Why hire me
 &lt;a class="heading-link" href="#why-hire-me"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Completed the &lt;strong&gt;Google Cybersecurity Professional Certificate&lt;/strong&gt;, covering SIEM tools, threat detection, and incident response fundamentals&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;6 months of internship experience&lt;/strong&gt; in security monitoring and structured incident documentation&lt;/li&gt;
&lt;li&gt;Practical grounding in &lt;strong&gt;CCNA-level networking&lt;/strong&gt; and &lt;strong&gt;CEH ethical hacking concepts&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Currently pursuing &lt;strong&gt;CompTIA Security+&lt;/strong&gt; and &lt;strong&gt;TryHackMe SOC Level 1&lt;/strong&gt; for hands-on validation&lt;/li&gt;
&lt;li&gt;Comfortable with &lt;strong&gt;Windows and Linux administration&lt;/strong&gt;, log analysis, and clear written communication for non-technical stakeholders&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="download-my-resume"&gt;
 Download my resume
 &lt;a class="heading-link" href="#download-my-resume"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;📄 &lt;a href="https://www.cyberkashif.com/files/Mohd_Kashif_SOC_Resume.pdf" &gt;Download Resume (PDF)&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Networking &amp; Security Explained: TCP Handshake, VPNs, DNS Attacks, and APTs - Part 10</title><link>https://www.cyberkashif.com/posts/tcp-handshake-vpn-dns-poisoning-apt-guide/</link><pubDate>Sun, 26 Jul 2026 10:30:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/tcp-handshake-vpn-dns-poisoning-apt-guide/</guid><description>&lt;h1 id="networking--security-fundamentals"&gt;
 Networking &amp;amp; Security Fundamentals
 &lt;a class="heading-link" href="#networking--security-fundamentals"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;hr&gt;
&lt;h2 id="ip-address-basics"&gt;
 IP Address Basics
 &lt;a class="heading-link" href="#ip-address-basics"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;An IP address is a &lt;strong&gt;unique numerical identifier&lt;/strong&gt; assigned to every device on a network.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Communication occurs through &lt;strong&gt;IP packets&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Data is broken into packets, sent, and reassembled at the destination.&lt;/li&gt;
&lt;li&gt;Each packet has a &lt;strong&gt;header&lt;/strong&gt; (control info) and &lt;strong&gt;payload&lt;/strong&gt; (data).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Encapsulation Process:&lt;/strong&gt;&lt;br&gt;
Data moves down the OSI stack → each layer adds its own header (Ethernet, IP, TCP, Application).&lt;/p&gt;</description></item><item><title>IPv4 Addressing &amp; Subnetting Explained: IP Classes, MAC Addresses, and SOC Scenarios - Part 9</title><link>https://www.cyberkashif.com/posts/ipv4-addressing-subnetting-ip-classes-guide/</link><pubDate>Sat, 25 Jul 2026 09:52:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/ipv4-addressing-subnetting-ip-classes-guide/</guid><description>&lt;h1 id="ipv4-addressing--networking-fundamentals"&gt;
 IPv4 Addressing &amp;amp; Networking Fundamentals
 &lt;a class="heading-link" href="#ipv4-addressing--networking-fundamentals"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;hr&gt;
&lt;h2 id="ipv4-addressing"&gt;
 IPv4 Addressing
 &lt;a class="heading-link" href="#ipv4-addressing"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;An IPv4 address (e.g., &lt;code&gt;192.168.1.10&lt;/code&gt;) is composed of &lt;strong&gt;32 bits&lt;/strong&gt; divided into four octets (8 bits each).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Each octet ranges from 0–255 (256 possible values).&lt;/li&gt;
&lt;li&gt;Structured with a &lt;strong&gt;network portion&lt;/strong&gt; and a &lt;strong&gt;host portion&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Example: &lt;code&gt;192.168.1.10&lt;/code&gt; → &lt;code&gt;192.168.1&lt;/code&gt; = network, &lt;code&gt;10&lt;/code&gt; = host.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Analogy:&lt;/strong&gt;&lt;br&gt;
Network = colony in a city&lt;br&gt;
Host = individual houses within that colony&lt;/p&gt;</description></item><item><title>OSI vs TCP/IP Models Explained: Protocols, Ports, and SOC Analysis - Part 8</title><link>https://www.cyberkashif.com/posts/osi-tcpip-networking-protocols-ports-guide/</link><pubDate>Fri, 24 Jul 2026 09:58:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/osi-tcpip-networking-protocols-ports-guide/</guid><description>&lt;h1 id="networking-fundamentals-osi-model-tcpip-protocols--ports"&gt;
 Networking Fundamentals: OSI Model, TCP/IP, Protocols &amp;amp; Ports
 &lt;a class="heading-link" href="#networking-fundamentals-osi-model-tcpip-protocols--ports"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;hr&gt;
&lt;h2 id="osi-open-systems-interconnection-model"&gt;
 OSI (Open Systems Interconnection) Model
 &lt;a class="heading-link" href="#osi-open-systems-interconnection-model"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The OSI model is a &lt;strong&gt;seven-layer framework&lt;/strong&gt; that explains how data travels across a network. Each layer serves a specific function and helps in troubleshooting networking issues.&lt;/p&gt;
&lt;h3 id="osi-layers"&gt;
 OSI Layers
 &lt;a class="heading-link" href="#osi-layers"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Physical Layer&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cables, hardware transmission, electrical signals&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Data Link Layer&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Lateral Movement, Privilege Escalation, MITM &amp; DoS: A Complete Cybersecurity Attack Guide - Part 7</title><link>https://www.cyberkashif.com/posts/lateral-movement-privilege-escalation-mitm-ddos-guide/</link><pubDate>Thu, 23 Jul 2026 10:49:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/lateral-movement-privilege-escalation-mitm-ddos-guide/</guid><description>&lt;h1 id="cybersecurity-concepts-lateral-movement-privilege-escalation-mitm--dos"&gt;
 Cybersecurity Concepts: Lateral Movement, Privilege Escalation, MITM &amp;amp; DoS
 &lt;a class="heading-link" href="#cybersecurity-concepts-lateral-movement-privilege-escalation-mitm--dos"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;hr&gt;
&lt;h2 id="lateral-movement"&gt;
 Lateral Movement
 &lt;a class="heading-link" href="#lateral-movement"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Lateral movement is the process of moving from one compromised system to another system within a network.&lt;/p&gt;
&lt;h3 id="why-attackers-perform-lateral-movement"&gt;
 Why Attackers Perform Lateral Movement
 &lt;a class="heading-link" href="#why-attackers-perform-lateral-movement"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;The first compromised system rarely contains valuable data.&lt;/li&gt;
&lt;li&gt;Attackers must move across the network to reach their true targets.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Example Attack Path:&lt;/strong&gt;
Phishing email → User laptop compromise → Lateral movement → Domain controller → Full network control&lt;/p&gt;</description></item><item><title>Understanding Password Attacks, Hashing, and Encryption: A Comprehensive Guide for Security Analysts - Part 6</title><link>https://www.cyberkashif.com/posts/password-attacks-hashing-encryption-guide/</link><pubDate>Wed, 22 Jul 2026 11:04:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/password-attacks-hashing-encryption-guide/</guid><description>&lt;h1 id="understanding-password-attacks-hashing-and-encryption-a-comprehensive-guide-for-security-analysts"&gt;
 Understanding Password Attacks, Hashing, and Encryption: A Comprehensive Guide for Security Analysts
 &lt;a class="heading-link" href="#understanding-password-attacks-hashing-and-encryption-a-comprehensive-guide-for-security-analysts"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;h2 id="introduction"&gt;
 Introduction
 &lt;a class="heading-link" href="#introduction"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;In today&amp;rsquo;s cybersecurity landscape, understanding the various methods attackers use to compromise credentials is essential for any security professional. This guide covers password attack techniques, hashing mechanisms, encryption fundamentals, and how Security Operations Center (SOC) analysts can detect and respond to these threats.&lt;/p&gt;</description></item><item><title>Understanding Cyber Threats: Malware, Phishing, and Social Engineering for SOC Teams - Part 5</title><link>https://www.cyberkashif.com/posts/malware-types-social-engineering-soc-guide/</link><pubDate>Tue, 21 Jul 2026 12:51:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/malware-types-social-engineering-soc-guide/</guid><description>&lt;h1 id="understanding-malware-types-and-social-engineering-a-comprehensive-guide-for-security-professionals"&gt;
 Understanding Malware Types and Social Engineering: A Comprehensive Guide for Security Professionals
 &lt;a class="heading-link" href="#understanding-malware-types-and-social-engineering-a-comprehensive-guide-for-security-professionals"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;h2 id="introduction"&gt;
 Introduction
 &lt;a class="heading-link" href="#introduction"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;In today&amp;rsquo;s interconnected digital landscape, understanding the various types of cyber threats is essential for any security operations center (SOC) analyst. This article explores the most common forms of malware and social engineering attacks, providing both technical insights and practical detection strategies that security professionals can implement in their daily operations.&lt;/p&gt;</description></item><item><title>The Ultimate Guide to Cyber Security Frameworks and SOC Operations - Part 4</title><link>https://www.cyberkashif.com/posts/cyber-security-frameworks-soc-operations-guide/</link><pubDate>Mon, 20 Jul 2026 12:29:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/cyber-security-frameworks-soc-operations-guide/</guid><description>&lt;h1 id="comprehensive-guide-to-cyber-security-frameworks-and-soc-operations"&gt;
 Comprehensive Guide to Cyber Security Frameworks and SOC Operations
 &lt;a class="heading-link" href="#comprehensive-guide-to-cyber-security-frameworks-and-soc-operations"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;hr&gt;
&lt;h2 id="1-cyber-kill-chain-framework"&gt;
 1. Cyber Kill Chain Framework
 &lt;a class="heading-link" href="#1-cyber-kill-chain-framework"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The Cyber Kill Chain is a foundational cybersecurity framework developed by Lockheed Martin that models the stages of a cyber attack. This linear model maps the attacker&amp;rsquo;s journey from initial reconnaissance to achieving their final objectives, providing defenders with a clear understanding of how attacks unfold.&lt;/p&gt;</description></item><item><title>From Indicators to Insights: Mastering TTPs, IOCs, and Alert Triage in the SOC - Part 3</title><link>https://www.cyberkashif.com/posts/ttps-vs-iocs-soc-guide/</link><pubDate>Mon, 20 Jul 2026 11:28:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/ttps-vs-iocs-soc-guide/</guid><description>&lt;h1 id="from-indicators-to-insights-mastering-ttps-iocs-and-alert-triage-in-the-soc"&gt;
 From Indicators to Insights: Mastering TTPs, IOCs, and Alert Triage in the SOC
 &lt;a class="heading-link" href="#from-indicators-to-insights-mastering-ttps-iocs-and-alert-triage-in-the-soc"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;hr&gt;
&lt;h2 id="introduction"&gt;
 Introduction
 &lt;a class="heading-link" href="#introduction"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;In the world of cybersecurity, understanding both the technical indicators of compromise and the behavioral patterns of attackers is essential for effective defense. This article explores three foundational concepts that every SOC analyst must master: &lt;strong&gt;Tactics, Techniques, and Procedures (TTPs)&lt;/strong&gt; , &lt;strong&gt;Indicators of Compromise (IOCs)&lt;/strong&gt; , and &lt;strong&gt;Alert Triage&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>Mastering SOC Security: Attack Vectors, Vulnerabilities, and Best Practices - Part 2</title><link>https://www.cyberkashif.com/posts/complete-guide-to-soc-security-vulnerabilities/</link><pubDate>Mon, 20 Jul 2026 10:32:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/complete-guide-to-soc-security-vulnerabilities/</guid><description>&lt;h1 id="understanding-security-operations-centers-and-cyber-vulnerabilities-a-comprehensive-guide"&gt;
 Understanding Security Operations Centers and Cyber Vulnerabilities: A Comprehensive Guide
 &lt;a class="heading-link" href="#understanding-security-operations-centers-and-cyber-vulnerabilities-a-comprehensive-guide"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;h2 id="security-operations-center-soc-models"&gt;
 Security Operations Center (SOC) Models
 &lt;a class="heading-link" href="#security-operations-center-soc-models"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;When organizations decide to establish security monitoring capabilities, they typically choose from three primary SOC deployment models:&lt;/p&gt;
&lt;h3 id="1-in-house-internal-soc"&gt;
 1. In-House (Internal) SOC
 &lt;a class="heading-link" href="#1-in-house-internal-soc"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;An internal SOC represents a fully self-managed security operations capability. The organization builds and operates its own security team, utilizing its proprietary tools, processes, and personnel. This model offers maximum control and customization but requires significant investment in infrastructure, talent acquisition, and ongoing operational costs.&lt;/p&gt;</description></item><item><title>What is a SOC? The Core Role of the Blue Team in Cybersecurity - Part 1</title><link>https://www.cyberkashif.com/posts/introduction-to-soc/</link><pubDate>Mon, 20 Jul 2026 09:52:10 +0530</pubDate><guid>https://www.cyberkashif.com/posts/introduction-to-soc/</guid><description>&lt;h1 id="the-role-of-a-soc-l1-analyst-the-first-line-of-cyber-defense"&gt;
 The Role of a SOC L1 Analyst: The First Line of Cyber Defense
 &lt;a class="heading-link" href="#the-role-of-a-soc-l1-analyst-the-first-line-of-cyber-defense"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;p&gt;In today&amp;rsquo;s threat landscape, cyberattacks are not a matter of &amp;ldquo;if,&amp;rdquo; but &amp;ldquo;when.&amp;rdquo; This is where the Security Operations Center (SOC) comes into play. At the heart of this defense mechanism is the SOC L1 Analyst—the first line of defense in an organization.&lt;/p&gt;
&lt;p&gt;The primary objective of a SOC is to minimize &lt;strong&gt;&amp;ldquo;Dwell Time,&amp;rdquo;&lt;/strong&gt; which refers to the duration an attacker remains undetected within a network. The longer an attacker stays hidden, the greater the risk of data breaches, which are often discovered only after customers or external agencies raise alarms. By then, the damage—both financial and reputational—can be catastrophic.&lt;/p&gt;</description></item><item><title>Autores de Hugo</title><link>https://www.cyberkashif.com/autores/autores-de-hugo/</link><pubDate>Thu, 05 Jan 2023 01:15:52 +0100</pubDate><guid>https://www.cyberkashif.com/autores/autores-de-hugo/</guid><description/></item><item><title>temas</title><link>https://www.cyberkashif.com/categoria/temas/</link><pubDate>Wed, 04 Jan 2023 23:21:18 +0100</pubDate><guid>https://www.cyberkashif.com/categoria/temas/</guid><description/></item><item><title>sintaxe</title><link>https://www.cyberkashif.com/categoria/sintaxe/</link><pubDate>Wed, 04 Jan 2023 23:21:06 +0100</pubDate><guid>https://www.cyberkashif.com/categoria/sintaxe/</guid><description/></item><item><title>Códigos curtos</title><link>https://www.cyberkashif.com/tags/shortcodes/_index.pt-br/</link><pubDate>Wed, 04 Jan 2023 11:51:36 +0100</pubDate><guid>https://www.cyberkashif.com/tags/shortcodes/_index.pt-br/</guid><description/></item><item><title>Projects</title><link>https://www.cyberkashif.com/projects/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.cyberkashif.com/projects/</guid><description>&lt;p&gt;Nothing to see here&amp;hellip; Move along!&lt;/p&gt;</description></item></channel></rss>