🔄 Topic

Starting the Google Cybersecurity Certificate by translating the introductory material into practical SOC analyst thinking.


🎯 Goal

Understand what an entry-level cybersecurity analyst actually does and connect the introductory phishing material to real investigation workflow.


🛠 What I Did

Today I worked through the opening part of Course 1 — Foundations of Cybersecurity.

The basic course material covered cybersecurity as a profession, common analyst responsibilities, core skills, transferable skills, and an introductory phishing exercise.

Because I have already been studying cybersecurity for a while, I did not treat this as brand-new theory. I used it to tighten my professional framing: what does a junior analyst need to observe, document, and escalate when something suspicious happens?

The most useful part was connecting phishing to actual SOC evidence instead of treating it as only a user-awareness topic.


🔗 Key Cybersecurity Connections

Phishing is one of the best early topics because it touches many evidence sources at once: email headers, URLs, DNS lookups, proxy logs, authentication logs, endpoint telemetry, and user reports.

A weak analyst says:

This email looks suspicious.

A stronger analyst says:

The message uses a lookalike sender domain, links to an unfamiliar host, targets multiple users, and should be checked against proxy and authentication logs for clicks and follow-on login activity.

That difference matters. SOC work is evidence-driven, not vibes-driven.


🔍 Investigation Questions

  • Who received the suspicious email?
  • Who sent it and does the domain match the claimed organization?
  • Are there links, attachments, QR codes, or credential-harvesting pages?
  • Did any user click the link?
  • Was there a login attempt after the click?
  • Was the login from a rare location, new device, or impossible travel pattern?
  • Did endpoint telemetry show Office, browser, script, or shell activity after interaction?
  • Should this be escalated, contained, or closed as benign?

🚨 Detection Opportunities

Useful detection ideas:

  • external sender using an internal-looking display name
  • lookalike domain in a URL
  • many users receiving the same unusual link
  • login from rare geography shortly after email delivery
  • Office document spawning a script interpreter

Example evidence chain:

email_received=true
sender_domain=payro11-example.com
link_clicked=true
login_after_click=true
login_country=rare_for_user
triage=possible_credential_phishing

🧭 MITRE ATT&CK Techniques

Relevant mappings depend on the observed behavior:

  • T1566 — Phishing
  • T1566.001 — Spearphishing Attachment
  • T1566.002 — Spearphishing Link
  • T1204 — User Execution
  • T1078 — Valid Accounts

🗺 Visual Investigation Diagram

Suspicious email
    ↓
User interaction
    ↓
URL / attachment evidence
    ↓
DNS / proxy / endpoint logs
    ↓
Authentication review
    ↓
Triage decision

⚠ Challenges

The challenge is not dismissing introductory material just because the vocabulary is simple. The terms are basic, but the analyst workflow behind them is not.

Phishing only becomes useful study material when I force myself to ask what evidence would prove or disprove compromise.


📚 What I Learned

I learned that analyst skill is not only technical knowledge. It is the ability to turn a vague report into a structured investigation.

A phishing email is not just a bad message. It is a possible chain from delivery to credential theft to account misuse.


➡ Next Steps

  • Build a phishing triage checklist
  • Create a fake phishing investigation with email, URL, DNS, proxy, and login evidence
  • Practice writing short escalation notes
  • Map each piece of evidence to the relevant log source

🧠 Reflection

This was a useful first step because it connected the certificate to the way I want to study: every concept should become a real scenario, a log source, an investigation question, or a detection idea.


🧩 Lessons Learned

What worked

Treating phishing as an evidence chain instead of an awareness topic.

What broke

The material feels too easy if I only read it as definitions.

Why it broke

The value is hidden unless I connect each concept to logs, alerts, and response decisions.

Fix / takeaway

For every simple concept, ask: what would a SOC analyst actually see?


📈 Skill Progression Context

This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.

Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.


😄 TL;DR

Phishing is not just a bad email. It is a full investigation chain.