Training Exercises
// hands-on labsPractical exercises to reinforce concepts. Use your own VM or a provided environment. Each lab links to official documentation.
SIEM · Splunk
Boss of the SOC v1
bots.splunk.com
Lab · AV
Install ClamAV Antivirus
docs.clamav.net
Lab · IDS
Install Suricata & Enable Rules
docs.suricata.io
Lab · Sysmon · Linux
Install Sysmon for Linux
github.com/microsoft/SysmonForLinux
Lab · Sysmon · Windows
Install Sysmon for Windows
learn.microsoft.com
Lab · SIEM
Forward Logs → Elasticsearch
elastic.co
Lab · SIEM
Forward Logs → Splunk Enterprise
splunk.com
Lab · Detection
Sigma Rules Repository
github.com/SigmaHQ/sigma
Lab · Detection
Sigma CLI — Convert Rules to SIEM Queries
github.com/SigmaHQ/sigma-cli
Lab · Malware
YARA Rules — Official Docs
yara.readthedocs.io
Lab · Malware
Getting Started with YARA Rules — Beginner's Guide
medium.com
Reference Library
// official standards & guidelinesPrimary references from ANSSI (French national cybersecurity authority), NIST, Microsoft, and industry bodies. French companies may be subject to ANSSI recommendations.
Asset Security
ANSSI
Guideline: Healthy Information System — 42 Measures
cyber.gouv.fr
ANSSI
Configuration Recommendations for GNU/Linux Systems
cyber.gouv.fr
ANSSI
Digital Hygiene for Mobile Phones
cyber.gouv.fr
ANSSI
Recommendations for Secure Administration of IT Systems
cyber.gouv.fr
NIST SP 800-12r1
An Introduction to Information Security
doi.org / NIST
NIST SP 800-92
Guide to Computer Security Log Management
doi.org / NIST
NIST SP 800-123
Guide to General Server Security
doi.org / NIST
Microsoft
Windows Security Baselines
learn.microsoft.com
Microsoft
App Control for Business — Design Guide
learn.microsoft.com
Microsoft
Example App Control Base Policies
learn.microsoft.com
OPTIONAL / SPECIFIC TOPICS — Asset Security
ANSSI · ICS
Managing Cybersecurity in Industrial Control Systems
cyber.gouv.fr
ANSSI · Maritime
Best Practices: Cybersecurity on Board Ships
cyber.gouv.fr
ANSSI · Hardware
Hardware Security Requirements for x86 Platforms
cyber.gouv.fr
ANSSI · Virtualization
Virtualization Security
cyber.gouv.fr
ANSSI · Databases
Relational Databases Security
cyber.gouv.fr
ANSSI · Cloud
Hosting Sensitive Information Systems in the Cloud
cyber.gouv.fr
NIST SP 800-44v2
Guidelines on Securing Public Web Servers
doi.org / NIST
Security Operations
NIST SP 800-61r3
Incident Response Recommendations
doi.org / NIST
NIST SP 800-86
Guide to Integrating Forensic Techniques into Incident Response
doi.org / NIST
NIST SP 800-83r1
Guide to Malware Incident Prevention and Handling
doi.org / NIST
NIST SP 800-150
Guide to Cyber Threat Information Sharing
doi.org / NIST
ANSSI · IR
Remediation: Active Directory Tier 0
cyber.gouv.fr
ANSSI · IR
Cyber Attacks & Remediation: Keys to Decision-Making
cyber.gouv.fr
ANSSI · IR
Cyber Attacks & Remediation: Managing Remediation
cyber.gouv.fr
ANSSI · Crisis
Crisis of Cyber Origin: Operational & Strategic Management
cyber.gouv.fr
Communication & Network Security
NIST SP 800-41r1
Guidelines on Firewalls and Firewall Policy
doi.org / NIST
NIST SP 800-94
Guide to Intrusion Detection and Prevention Systems (IDPS)
doi.org / NIST
ANSSI
Best Practices: Acquiring and Using Domain Names
cyber.gouv.fr
ANSSI
OpenSSH Secure Use Recommendations
cyber.gouv.fr
ANSSI
Recommendations for Securing Networks with IPsec
cyber.gouv.fr
ANSSI
BGP Configuration Best Practices
cyber.gouv.fr
ANSSI
Security Recommendations for TLS
cyber.gouv.fr
Security Assessment & Risk
ANSSI
EBIOS Risk Manager Method
cyber.gouv.fr
NIST
Risk Management Framework (RMF)
nist.gov
NIST SP 800-30r1
Guide for Conducting Risk Assessments
doi.org / NIST
NIST SP 800-115
Technical Guide to Information Security Testing and Assessment
doi.org / NIST
PTES
Penetration Testing Execution Standard — Technical Guidelines
pentest-standard.org
Defensive Techniques & Threat Intelligence
Lockheed Martin
Cyber Kill Chain Framework
lockheedmartin.com
MITRE ATT&CK
ATT&CK Resources
attack.mitre.org
MITRE ATT&CK
Getting Started with ATT&CK Detection
medium.com / MITRE
ANSSI
Data Leak Prevention
cyber.gouv.fr
ANSSI
Distributed Denial of Service (DDoS)
cyber.gouv.fr
ANSSI
Ransomware Attacks: Prevention and Incident Response
cyber.gouv.fr
ANSSI
Zero Trust Architecture
cyber.gouv.fr
ANSSI
Golden Rules for Backup
cyber.gouv.fr
ANSSI
Mapping the Information System
cyber.gouv.fr
Reference Books
// recommended readingsEssential reading list covering SOC operations, network analysis, malware, memory forensics, and penetration testing.
978-1091493896
Blue Team Handbook: SOC, SIEM, and Threat Hunting (V1.02)
SOC · SIEM · THREAT HUNTING
978-0321336323
Virtual Honeypots: From Botnet Tracking to Intrusion Detection
HONEYPOTS · DECEPTION
978-1593278021
Practical Packet Analysis
NETWORK · FORENSICS
978-1491910955
Network Security Assessment: Know Your Network
NETWORK · ASSESSMENT
978-1593277505
Attacking Network Protocols
NETWORK · EXPLOITATION
978-1118824993
The Art of Memory Forensics
FORENSICS · MALWARE · WINDOWS/LINUX/MAC
978-1593272906
Practical Malware Analysis
MALWARE · REVERSE ENGINEERING
978-1593272883
Metasploit: The Penetration Tester's Guide
PENTEST · EXPLOITATION
978-1593271442
Hacking, 2nd Edition
EXPLOITATION · FUNDAMENTALS
978-0979958717
Nmap Network Scanning
RECON · NETWORK DISCOVERY
978-0321294319
Rootkits: Subverting the Windows Kernel
ROOTKITS · KERNEL
978-0735684188
Windows Internals, Part 1
WINDOWS · OS INTERNALS
978-0135462409
Windows Internals, Part 2
WINDOWS · OS INTERNALS
978-1718503359
Evading EDR: The Definitive Guide to Defeating Endpoint Detection Systems
EDR · EVASION
978-1787399051
RTFM: Red Team Field Manual
RED TEAM · REFERENCE
978-1449392680
Introducing Regular Expressions
REGEX · FUNDAMENTALS
978-0596528126
Mastering Regular Expressions
REGEX · ADVANCED