October 10, 2026
Thinking Like a SOC Analyst: What I Learned Completing KC7 Security Analyst I
Six investigations, one skill set: turning raw logs into answers.
By Muhammad Fahad
3 min read
By Muhammad Fahad
Overview
Most beginner training teaches you what tools do. KC7: The Cyber Detective Game asks something harder: given only logs, what happened, and how do you prove it?
The Security Analyst I path puts you in the role of a SOC analyst across realistic incidents. You work in Azure Data Explorer and query with KQL (Kusto Query Language). Each scenario gives you a question, and you answer it with evidence.
I'm sharing this to document what I learned, and the skills each module built. I've left out case answers so the game stays fun for anyone who wants to try it.
Skills at a Glance
- Phishing analysis: A Rap Beef, CloutHaus
- Social engineering detection: CloutHaus
- Account compromise investigation: CloutHaus, A Scandal in Valdoria
- Attack timeline building: A Scandal in Valdoria, Jojo's Hospital
- Threat intelligence pivoting: VirusTotal Fundamentals
- KQL querying: every module, especially KQL 101
- Ransomware investigation: Jojo's Hospital
Module Breakdown
๐ง A Rap Beef: Phishing and Intrusion Basics
What it covers: a first full investigation, from suspicious activity to confirmed intrusion.
Skills practiced
- Spotting phishing indicators in emails
- Reading security logs to trace an intrusion from start to finish
- Pivoting from one indicator (an IP or domain) to related activity
Takeaway: a clean-looking email isn't a safe email. Behavior in the logs tells the real story.
๐ฑ CloutHaus: Social Media to Account Compromise
What it covers: how public information can be used to attack a person and then their employer.
Skills practiced
- Recognizing social engineering and spear-phishing tactics
- Detecting malicious email forwarding rules
- Understanding the real impact of missing MFA
Takeaway: security controls only work when they're applied everywhere. One unprotected account can undo the rest.
๐๏ธ A Scandal in Valdoria: Building an Attack Timeline
What it covers: a multi-stage incident where you correlate events across several log sources.
Skills practiced
- Core KQL:
where,take,distinct - Time-based filtering
- Correlating events from different tables into one timeline
- Interpreting suspicious PowerShell commands
Takeaway: a single log line is rarely the answer. The timeline is.
๐ฆ VirusTotal Fundamentals: Threat Intelligence
What it covers: using VirusTotal as an investigation platform, not just a detection score.
Skills practiced
- Telling benign files from malicious ones
- Pivoting from a single indicator to the wider threat
- Understanding what a code-signing certificate does and doesn't prove
Takeaway: a low detection count isn't a green light, and "signed" doesn't mean "safe."
๐ KQL 101: Query Language Foundations
What it covers: the fundamentals that make every other module faster.
Skills practiced
- Choosing the right table for the question
- Filtering with
where,contains, andhas - Combining logical operators for efficient queries
- Pivoting across tables
Two patterns I use constantly:
- Precision with
hasvscontains
// contains = partial matches (more noise)
Email | where subject contains "<keyword>"
// has = whole-word matches (more precise)
Email | where subject has "<keyword>"// contains = partial matches (more noise)
Email | where subject contains "<keyword>"
// has = whole-word matches (more precise)
Email | where subject has "<keyword>"- Scaling a lookup with
let
let targets =
Employees
| where name has "<name>"
| distinct ip_addr;
OutboundNetworkEvents
| where src_ip in (targets)let targets =
Employees
| where name has "<name>"
| distinct ip_addr;
OutboundNetworkEvents
| where src_ip in (targets)Takeaway: the let pattern turns one indicator into a full list of affected users, machines, or connections in a single query.
๐ Jojo's Hospital: Ransomware Investigation
What it covers: an end-to-end ransomware case that ties every earlier skill together.
Skills practiced
- Scoping impact: which systems and files are affected
- Forming the right analytical questions before writing queries
- Tracing activity backward to find how the attacker got in
- Answering each question with log evidence in KQL and ADX
Takeaway: ransomware is the last step of an attack, not the first. The earlier signs are in the logs if you know where to look.
Key Lessons
- Verdicts are a starting point. Email filters and detection scores can miss real threats.
- Knowing the right table matters. Email, network, file, process, and authentication logs each answer different questions.
- Pivoting is the core skill. One IP, domain, or username should lead you to the next piece of evidence.
- Good questions beat clever queries. Syntax can be looked up. Investigative thinking has to be built.
- Logs don't lie. You just have to ask them the right questions.
How This Maps to Real SOC Work
- Alert triage: deciding quickly whether an alert is real
- Incident scoping: finding every affected user and system
- Timeline reconstruction: documenting what happened and when
- Threat intel enrichment: adding context to indicators
- Reporting: explaining findings with evidence
Final Thoughts
KC7 changed how I approach investigations: ask a clear question, pick the right data source, follow the evidence one pivot at a time.
If you're starting out in blue team work, I'd recommend KC7. It's free and hands-on, and it teaches you to think like an analyst.
Tags: Cybersecurity, SOC Analyst, KQL, Blue Team, Threat Detection