Jbird - SOC Lab Collection

12 comprados + 6 freebies. ~340 paginas. Todos los .md formateados con estructura CySA+ style. Listos para BMO y traducción a español.

SOC Investigation Workbooks (10)

#WorkbookArchivo
1Impossible Travelimpossible-travel-investigation-workbook.md
2Password Spraypassword-spray-investigation-workbook.md
3BECbec-investigation-workbook.md
4Suspicious PowerShellpowershell-investigation-workbook.md
5Malware Alertsmalware-alert-investigation-workbook.md
6VPN Alertsvpn-alert-investigation-workbook.md
7Insider Threatinsider-threat-investigation-workbook.md
8Privileged Account Abuseprivileged-account-abuse-investigation-workbook.md
9Data Exfiltrationdata-exfiltration-investigation-workbook (1).md
10Ransomwareransomware-investigation-workbook.md

Referencias individuales

GuiaArchivoPrecio
Windows Event Log AnalysisWindows_Event_Log_Analysis_Guide.md$14.99
IAM Crash CourseIdentity and Access Management Crash Course.md$9.99

Freebies

RecursoArchivo
Resume Red Flagsjbird-resume-red-flags.md
10 Acronyms Interview Prep10_Cybersecurity_Acronyms_Interview_Prep.md
Certification Order Cheat SheetCybersecurity_Certification_Order_Cheat_Sheet.md
Career Path Cheat SheetCybersecurity_Career_Path_Cheat_Sheet.md
SOC Interview 10 QuestionsSOC_Interview_10_Questions.md
Detecting Malicious Activity on HostsDetecting Malicious Activity on Hosts.md

Attack Chain

Vol 4 PowerShell -> Vol 5 Malware -> Vol 6 VPN -> Vol 8 Privileged Account -> Vol 9 Data Exfil -> Vol 10 Ransomware

Orden recomendado

  1. Windows Event Log Analysis ” referencia de EIDs (leer primero)
  2. Impossible Travel (Vol 1)
  3. Seguir orden numérico 2 -> 10
  4. IAM Crash Course ” cuando toque IAM/entrevistas

Formato

Todos los archivos siguen el mismo estilo que el bundle CySA+:

  • Frontmatter completo con tags, author, source, role, description
  • Estructura con #, ##, ### para navegacion
  • Tablas markdown formateadas
  • Callouts con > **ETIQUETA**: texto
  • Bloques de código con syntax highlighting
  • Sin artefactos PDF