Day 68 of Becoming a SOC Analyst — SOC136 Data Leak via Mailbox Forwarding Detected (True Positive)
User [email protected] attempted to forward an email containing plaintext credential pairs — root, john, bill, and admin with associated passwords — to an external Yandex address [email protected]. Mail security controls blocked the transmission before it left the organisation, preventing the exfiltration. Whether accidental or intentional, credentials were involved and the destination was external — that's enough to classify as true positive and escalate for user confirmation and mandatory credential rotation. Walked through the full triage: email content review, external destination analysis, mail server log confirmation, transmission block verification, MITRE mapping (T1567, T1114), and confirming true positive with escalation for credential rotation.
00:00 Day 68 intro
00:15 Alert Details
00:41 Investigation
02:510 Playbook Answers
05:20 5w Log
08:14 Result
SOC136 - Data Leak via Mailbox Forwarding Detected
Scenario sourced from LetsDefend.io — one of the best hands-on SOC analyst training platforms out there.
Highly recommend if you're on the same path. I'm documenting every day of my journey to landing a Level 1 SOC Analyst role — the wins, the grinds, and everything in between.
🔵 What I Cover
Threat Detection · Alert Triage · SIEM Analysis · Log Analysis · Incident Response · Blue Team Tools
🚨 Open to Work — Seeking a Level 1 SOC Analyst role in Melbourne or Remote (AU)
📂 Portfolio → inksec.io
💼 LinkedIn → linkedin.com/in/tate-pannam-8b64b23a3
If you chose the red pill... 0x74617465.sh
#SOCAnalyst #BlueTeam #Cybersecurity #DataLeak #EmailForwarding #CredentialExfiltration #InsiderThreat #IncidentResponse #SIEM #Day68 #CyberSecurityJourney #Melbourne #LetsDefend #LetsDefendSOC #ThreatHunting #InfoSec #BlueTeamSecurity