Cheat sheet

SOC analyst cheat sheet

Ports, Windows event IDs, email authentication, checklists and starter SIEM queries — everything in one place.

Updated October 2026 · Bookmark this page

A one-page reference for the facts SOC analysts look up most often. Use it while you study, during practice investigations and before interviews.

Common ports and protocols

PortProtocolWhy it matters
20/21FTPFile transfer; credentials sent in clear text
22SSHRemote administration; watch for brute force
23TelnetLegacy remote access; unencrypted
25SMTPEmail delivery between servers
53DNSName resolution; abused for tunneling
67/68DHCPAutomatic IP addressing
80HTTPUnencrypted web traffic
88KerberosWindows domain authentication
110 / 995POP3 / POP3SEmail retrieval
123NTPTime synchronisation
135RPCWindows remote procedure calls
137–139NetBIOSLegacy Windows networking
143 / 993IMAP / IMAPSEmail retrieval
389 / 636LDAP / LDAPSDirectory queries (Active Directory)
443HTTPSEncrypted web traffic; most C2 hides here
445SMBWindows file sharing; lateral movement and ransomware
1433MS SQLMicrosoft SQL Server
3306MySQLMySQL database
3389RDPRemote Desktop; never expose to the internet
5985 / 5986WinRMPowerShell remoting; used for lateral movement

Windows Security event IDs

These appear in the Windows Security log (7045 is in the System log). Some require audit policies to be enabled.

Event IDMeaningInvestigation tip
4624Successful logonCheck logon type, source IP and account
4625Failed logonMany in a short time suggests brute force or password spraying
4634LogoffHelps define session length
4648Logon with explicit credentialsCan indicate runas or lateral movement
4672Special privileges assignedAdmin-level logon
4688Process createdRequires auditing; shows command lines if enabled
4697 / 7045Service installedCommon persistence and lateral movement technique
4698Scheduled task createdCommon persistence technique
4720User account createdUnexpected accounts are a red flag
4724Password reset attemptCheck who reset whose password
4728 / 4732Member added to security groupWatch privileged groups such as Domain Admins
4740Account locked outOften follows brute-force attempts
4776Credential validation (NTLM)Useful for spotting password spraying
1102Audit log clearedHighly suspicious: attackers hide their tracks

Windows logon types (in event 4624/4625)

TypeNameExample
2InteractiveKeyboard logon at the machine
3NetworkAccess to a share or service over the network
4BatchScheduled tasks
5ServiceService start-up
7UnlockWorkstation unlocked
10RemoteInteractiveRDP session
11CachedInteractiveLogon with cached credentials, e.g. offline laptop

Sysmon event IDs

Sysmon is a free Microsoft Sysinternals tool that adds detailed endpoint logging. These are the IDs analysts use most.

IDEventWhy it is useful
1Process creationFull command line, hashes and parent process
3Network connectionWhich process connected where
7Image loadedDLLs loaded by a process
11File createdNew files, e.g. dropped payloads
13Registry value setPersistence via Run keys
22DNS queryWhich process looked up which domain

Email authentication: SPF, DKIM and DMARC

  • SPF — checks whether the sending server is allowed to send for the domain in the envelope sender (Return-Path).
  • DKIM — a cryptographic signature proving the message was not altered and was signed by the domain in the signature.
  • DMARC — tells receivers what to do when SPF/DKIM fail and checks that the visible From domain aligns with them.

A pass does not mean an email is safe: attackers can register look-alike domains with perfect SPF, DKIM and DMARC. Always check the actual domain.

Phishing analysis checklist

  1. Who is the real sender? Compare the display name, From address, Reply-To and Return-Path.
  2. Do SPF, DKIM and DMARC pass, and for which domain?
  3. Is the sending domain new or a look-alike (for example micros0ft-support.com)?
  4. Where do links really point? Hover or extract URLs without clicking; check reputation.
  5. Are there attachments? Check file type, hash and reputation — never open them on your workstation.
  6. How many users received it, and did anyone click, reply or enter credentials?
  7. Act: remove the message, block indicators, reset affected credentials, document and notify.

Full walkthrough: how to analyze a phishing email.

Alert triage checklist

  1. What triggered the alert, and what is the rule designed to detect?
  2. Which user, host and IP addresses are involved? Are they critical?
  3. Is the activity normal for this user or system? Compare with history.
  4. What happened just before and just after? Build a short timeline.
  5. Is there corroborating evidence in another source (identity, endpoint, network, email)?
  6. Classify: true positive, benign true positive or false positive.
  7. Set severity, act or escalate, and document your reasoning.

Starter SIEM queries

Field and table names vary between environments, so treat these as patterns to adapt.

KQL (Microsoft Sentinel): accounts with many failed sign-ins in the last hour

SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != "0"
| summarize Failures = count() by UserPrincipalName, IPAddress
| where Failures > 10
| order by Failures desc

SPL (Splunk): failed Windows logons by account and source

index=wineventlog EventCode=4625 earliest=-1h
| stats count by Account_Name, Source_Network_Address
| where count > 10
| sort - count

KQL: processes launched by Office applications

DeviceProcessEvents
| where InitiatingProcessFileName in~ ("winword.exe","excel.exe","outlook.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine

Quick severity guide

SeverityTypical examples
CriticalActive ransomware, confirmed domain admin compromise, data exfiltration in progress
HighConfirmed account compromise, malware executing on a host, successful phishing with credential entry
MediumSuspicious activity needing investigation, malware blocked but user clicked, policy violations with risk
LowBlocked attempts, informational alerts, clear false positives to tune

Every organization defines severity differently — always follow your team’s matrix.

Use it on a real case

Put the cheat sheet to work.

Investigate realistic alerts where these event IDs, ports and checks actually matter.

Start free. No experience required.