Page 2 of 6.
What is WHOIS and how to read it.
WHOIS explained: what a domain lookup returns, how to read every field, why GDPR redacts it, RDAP, IP WHOIS via the RIRs, and tools to investigate a domain.
Domains vs subdomains: how to enumerate them.
What a domain is made of, why subdomains are an attack surface, and how to enumerate them – passive and active – with crt.sh, Amass, subfinder and more.
SOC team roles and tiers explained.
Inside a SOC: the tier model, every role from Tier 1 analyst to SOC manager, how alerts escalate, shift work, and the realistic path in and up.
SOC tools: SIEM, SOAR, EDR and more.
The SOC toolstack by category – SIEM, EDR/XDR, SOAR, NDR, threat intel, sandboxes and enrichment – with real OSS and commercial tools linked.
What is a SOC? Security Operations Center.
A SOC is the team that monitors, detects, triages, and responds to threats around the clock. What a SOC really does, how an alert flows, and how to run one.
What is OSINT? Tools and workflow.
OSINT turns open, public sources into intelligence, not hacking. The intelligence cycle, -INT disciplines, legal limits, OPSEC, a workflow and real tools.