What the SOC Analyst path actually taught me — running my own SIEM alongside it
Going through HTB's SOC Analyst path while running a purple team lab changed what stuck. The detections aren't the point. Seeing where they break is.
Going through HTB's SOC Analyst path while running a purple team lab changed what stuck. The detections aren't the point. Seeing where they break is.
The rule is six lines of XML. The part that actually mattered was a query I ran before writing any of it.