Browse CTFs New CTF Sign in
Back to Learning Paths
Cyber Security Operations Analyst
Associate Wave 1

Cyber Security Operations Analyst

40.0h estimated 4 Courses

Associate-level certification aligned to CCSSF Cyber Security Operations Analyst. Covers SOC operations, PCAP analysis, SIEM/log correlation, memory forensics, and OSINT/CTI.

Sign in to enroll

PCAP, Protocol Analysis and SOC Network Triage

34 cards

Detecting Advanced DNS Tunneling Evasion via Slow-Rate Exfiltration and Multi-Domain Correlation

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing HTTP Sessions via Multi-Request Correlation, Credential and Object Recovery

network_forensics_pcap Difficulty 1–5 30 min

Detecting TLS Fingerprint Anomalies via JA3/JA3S Computation and Malware Client Identification

network_forensics_pcap Difficulty 1–5 30 min

Detecting ICMP Covert Channels via Payload Anomaly Identification and Hidden Data Extraction

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing FTP Data Exfiltration via Passive Mode Analysis and TCP Stream Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing Advanced SMTP Exfiltration via MIME Multipart Parsing and Encoded Attachment Recovery

network_forensics_pcap Difficulty 1–5 30 min

Identifying IRC Botnet C2 via PRIVMSG Command Pattern Analysis and Bot Fingerprinting

network_forensics_pcap Difficulty 1–5 30 min

Detecting Kerberoasting and AS-REP Roasting via TGS-REQ Analysis and Ticket Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing WebSocket Data Exfiltration via Frame Demasking, Payload Extraction and Protocol Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Extracting Modbus Register Data via ICS/OT Protocol Forensics and Unauthorized Read Detection

network_forensics_pcap Difficulty 1–5 30 min

Recovering Corrupted PCAP Files via Magic Byte Forensics and Partial Capture Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Volatility 3 Advanced Analysis: Symbol Tables, Namespaced Plugins and Cross-Layer Memory Correlation

network_forensics_pcap Difficulty 1–5 30 min

Simulation

reverse_engineering Difficulty 1–5 30 min

DOCX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX hidden text forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision comment forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX acrostic steganography

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision history (track changes)

network_forensics_pcap Difficulty 1–5 30 min

DOCX extended app properties forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden cell forensics (white-on-white)

network_forensics_pcap Difficulty 1–5 30 min

XLSX named range forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX cell comment forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX very-hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

Shellcode Injection and Execution: NX-Free Environment Exploitation and NOP Sled Delivery

network_forensics_pcap Difficulty 1–5 30 min

Kubernetes RBAC to S3 Pivot: Pod Service Account Lateral Movement to Cloud Storage

network_forensics_pcap Difficulty 1–5 30 min

IAM Privilege Escalation Chain: AssumeRole, PassRole and CreatePolicyVersion Abuse Paths

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing Ransomware Infection Vectors from Multi-Source Log Evidence

network_forensics_pcap Difficulty 1–5 30 min

C2 Beaconing Detection via Log Interval Analysis and Temporal Correlation

network_forensics_pcap Difficulty 1–5 30 min

Correlating SQLi, XSS, LFI and RCE Attack Patterns Across Web Server Access Logs

network_forensics_pcap Difficulty 1–5 30 min

Detecting Malicious Service Persistence via Windows Event 7045 and Systemd Unit Forensics

network_forensics_pcap Difficulty 1–5 30 min

Detecting DNS Exfiltration Through Entropy-Based Subdomain Anomaly Analysis

network_forensics_pcap Difficulty 1–5 30 min

Instagram-to-Twitter Persona Pivot: Cross-Platform Handle Correlation and Profile Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Logs, SIEM Correlation and Threat Hunting

16 cards

Correlating Multi-Host Authentication Anomalies to Detect Lateral Movement

log_analysis_siem Difficulty 1–5 30 min

Correlating Audit Events Across Linux and Windows Privilege Escalation Transitions

log_analysis_siem Difficulty 1–5 30 min

QR code decode

log_analysis_siem Difficulty 1–5 30 min

Sigreturn-Oriented Programming: Signal Frame Hijacking for Full CPU Register Control with Minimal Gadgets

log_analysis_siem Difficulty 1–5 30 min

Morse Code Decoding: Timing Analysis, Delimiter Identification and Transcription Methodology

log_analysis_siem Difficulty 1–5 30 min

Bacon cipher

log_analysis_siem Difficulty 1–5 30 min

Zero-width steganography

log_analysis_siem Difficulty 1–5 30 min

Brainfuck encoding

log_analysis_siem Difficulty 1–5 30 min

NATO phonetic alphabet

log_analysis_siem Difficulty 1–5 30 min

Multi-layer encoding chain

log_analysis_siem Difficulty 1–5 30 min

QR Code Forensics: Error Correction Analysis and Partially Damaged Payload Reconstruction

log_analysis_siem Difficulty 1–5 30 min

Baudot encoding

log_analysis_siem Difficulty 1–5 30 min

Leetspeak obfuscation

log_analysis_siem Difficulty 1–5 30 min

Azure RBAC Misconfiguration: Subscription-Scope Role Assignments and Service Principal Abuse

log_analysis_siem Difficulty 1–5 30 min

AWS Service Control Policy Misconfiguration: Cross-Account Permission Escalation

log_analysis_siem Difficulty 1–5 30 min

S3 Bucket Policy Misconfiguration: Public Access, Cross-Account Grants and Transport Gaps

log_analysis_siem Difficulty 1–5 30 min

Memory Forensics, Malware Signals and Host Triage

15 cards

In-Memory Password Recovery: LSASS Analysis, WDigest Extraction and Credential Cache Forensics

memory_forensics Difficulty 1–5 30 min

Detecting Process Injection: Identifying DLL Injection, Hollowing and Reflective Loading Artifacts

memory_forensics Difficulty 1–5 30 min

Identifying Log Tampering Through Clearance Events and Sequence Gap Analysis

memory_forensics Difficulty 1–5 30 min

Advanced Multi-Layer Encoding with Compression: gzip/zlib Layer Identification and Programmatic Decoding

reverse_engineering Difficulty 1–5 30 min

Custom VM Obfuscation Reversal: Dispatcher Loop Analysis and Python Disassembler Construction

reverse_engineering Difficulty 1–5 30 min

Password check

reverse_engineering Difficulty 1–5 30 min

License key generation

reverse_engineering Difficulty 1–5 30 min

Simple Buffer Overflow Without Protections: Return Address Overwrite and Program Flow Redirection

reverse_engineering Difficulty 1–5 30 min

ret2libc on x86-64: GOT-Based libc Leak, ROP Gadget Setup and system("/bin/sh") Invocation

reverse_engineering Difficulty 1–5 30 min

ROP Chain Construction: Gadget Chaining for execve Syscall with Stack Alignment and Bad-Byte Avoidance

reverse_engineering Difficulty 1–5 30 min

Canary Brute-Force on Forking Servers: Byte-by-Byte Enumeration Exploiting fork() Memory Inheritance

reverse_engineering Difficulty 1–5 30 min

OAuth-to-Kubernetes-to-Git OSINT Pivot: Authorization Flow Exploitation Across Infrastructure Services

memory_forensics Difficulty 1–5 30 min

Corporate OSINT Chain: WHOIS, LDAP and SMTP Correlation for Organizational Intelligence

memory_forensics Difficulty 1–5 30 min

Social Media-to-Map-to-Stego-to-Chat Pivot: Multi-Modal OSINT Chain Across Four Data Domains

memory_forensics Difficulty 1–5 30 min

Full Corporate Breach Simulation: Five-Service OSINT Chain from Reconnaissance to Data Exfiltration

memory_forensics Difficulty 1–5 30 min

OSINT and CTI for SOC Enrichment

19 cards

Underground Forum-to-Pastebin OSINT Pivot: Alias Correlation and Leaked Document Discovery

osint_soc_enrichment Difficulty 1–5 30 min

Email-to-S3 OSINT Pivot: SMTP Reconnaissance Chaining to Cloud Storage Data Exposure

osint_soc_enrichment Difficulty 1–5 30 min

WHOIS-to-Employee OSINT Chain: Domain Registration Pivoting to Internal Staff Identification

osint_soc_enrichment Difficulty 1–5 30 min

Social-to-Chat OSINT Pivot: Instagram-to-Messaging Platform Identity Correlation

osint_soc_enrichment Difficulty 1–5 30 min

AWS Cognito Unauthenticated Identity Pool Exploitation: Anonymous Credential Escalation

osint_collection Difficulty 1–5 30 min

Terraform State Manipulation: Injecting Malicious Resource Definitions via Backend Write Access

osint_collection Difficulty 1–5 30 min

AWS CloudFormation Credential Exposure: Extracting Secrets from Stack Templates

osint_collection Difficulty 1–5 30 min

AWS Lambda Execution Role Privilege Escalation: Function Invocation for IAM Abuse

osint_collection Difficulty 1–5 30 min

AWS Secrets Manager Access Control Weaknesses: Scoping IAM Policies for GetSecretValue

osint_collection Difficulty 1–5 30 min

AWS Confused Deputy Attack: Cross-Account Role Assumption Without External ID Enforcement

osint_collection Difficulty 1–5 30 min

Reconstructing SMTP Email Sessions and Extracting Attachments from Network Traffic Captures

osint_collection Difficulty 1–5 30 min

Parsing FTP Command and Response Traffic with Passive Mode Data Channel Reconstruction

osint_collection Difficulty 1–5 30 min

Parsing Telnet IAC Command Sequences and Reconstructing Plaintext Sessions from PCAP

osint_collection Difficulty 1–5 30 min

Reconstructing IRC Sessions via Protocol PCAP Analysis and Channel Message Content Recovery

osint_collection Difficulty 1–5 30 min

Reconstructing LDAP Directory Queries via PCAP Analysis and Enumeration Pattern Detection

osint_collection Difficulty 1–5 30 min

Analyzing WebSocket PCAP Captures via HTTP Upgrade Detection and Frame Payload Extraction

osint_collection Difficulty 1–5 30 min

Reconstructing SIP Call Dialogs and Extracting RTP Stream Parameters for VoIP Forensics

osint_collection Difficulty 1–5 30 min

Enumerating Local Services via mDNS PCAP Multicast Record Analysis and Host Fingerprinting

osint_collection Difficulty 1–5 30 min

Interpreting Modbus/TCP Function Codes and Extracting PLC Register Values from PCAP

osint_collection Difficulty 1–5 30 min
🏅

CTFFactory Cyber Security Operations Analyst — Associate

Associate credential — awarded upon completion