← Back to list

DAY 1 - 30 Day MyDFIR SOC Analyst Challenge!

You can install draw.io on your computer or use it through Google Drive.

Zen · 2025-12-03 13:46 · 6 claps · 9.6 min read
#mydfir #soc-analyst #soc-analyst-training #30-day-challenge #draw-io
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

DAY 1 - 30 Day MyDFIR SOC Analyst Challenge!

You can install draw.io on your computer or use it through Google Drive.

I used draw.io in the past for IVR diagrams, logical topologies, mind maps to summarize notes…

Setup on Google Drive

I created a new folder, and I got to it. I right-click inside of it. I go to “More”, then I click on “Connect more apps”. I get this search engine, and I search for draw.io.

In the results, it’s this one in red.

I install it.

After that, I go back to my folder. I right-click in the folder, I go to “More”, then I click on the newly installed draw.io.

It will ask for authorization. You authorize it.

This is what it should look like. In my case, I’m in dark mode.

You click in the top left to change the name of the diagram.

You rename it with the .drawio extension.

Here’s the new name of the file.

In this challenge, I will recreate the logical diagram MyDFIR creates in his video.

I will start searching for a server.

I can click on more results to see more.

I’ll pick the traditional server. I click on it, and it will appear.

To make copies, I click on it.

Once it’s selected, I can type the combination CTRL and D to make a copy.

I want six servers, so I did it six times.

For a cloud provider, I can pick this rectangle.

I expand it over the servers since it will be used to create the six servers.

I go to the General section and click on text.

The cloud provider is Vultr, so I wrote that inside the rectangle with the text.

I moved the text by doing a drag and drop to the top left. To see the servers, I right-click inside the rectangle, then click on “To Back”.

I can see all the servers.

I name the servers: Elastic & Kibana, Windows Server RDP Enabled, Ubuntu Server SSH Enabled, Fleet Server, Ticket Server, and the C2 Server. I place the C2 Server outside.

To color the C2 Server, I click on it to select it. Then, in the Style area, I click on the dropper icon.

In the rectangle at the bottom, I move the button around the red color. Then I click in the big square on the shade I want.

I then add a VPC (virtual private cloud), which puts all the servers in a private network. I search for VPC in the search bar and pick this one.

I drag it into the cloud provider rectangle and adjust it. The servers should be inside it.

If you wanna link an element to another, click on it, then hover on the side you wanna connect, you should see a blue arrow.

You click on the blue arrow, then drag it to the other element you wanna link it to, and let go.

I do the same thing with the Ubuntu server.

I also linked it to the Fleet server.

To write something on the link, you double-click where you want the text to be. In my case, I want it in the middle, so that’s where I double-click.

You can then write what you want. If it’s a long text, just add a new line to break it so it doesn’t take over the entire thing.

I do the same on the other side:

I then connect the fleet server to the Elastic & Kibana server.

Now I want a bidirectional link, but here it’s only in one direction. I click on the arrow to select it:

On the right, I go to Style and click on this scrolling menu. This lets you decide what you want on the other end of the arrow.

I pick the first one.

I also changed the color of the bidirectional arrow to orange. This would represent the direction of the traffic. Still in Style, I can go through the options until I find the color. That’s not the only way to change the color of an item.

I also want to change the pattern of the arrow. I click on this scrolling menu and pick the fourth option, a dashed line.

Here’s the result.

I double-click in the middle of it to write: Manage agents.

I now link the osTicket Server to the Elastic & Kibana Server.

I followed the same methodology for the previous one, except this line will be yellow.

I now link the Windows Server with RDP enabled to the Elastic & Kibana Server.

This is what it looks like.

I want to make it a straight line. I click on it to select it.

Then at the right in the Style section, I click on this scrolling menu and pick the straight option.

This is the result.

I repeat the same process from the Ubuntu Server to the Elastic & Kibana Server.

I changed the pattern for both new lines. I can press CTRL while I click on both lines to select them. Then I pick the fourth option in the scrolling menu as shown previously.

I now turn them blue through another method. In the Style section, I click on the dropper icon.

I can now pick the color I want and click on Apply.

This is what it looks like.

I need to add the network information, so I go to the General section and select the Text element by clicking on it.

I type in the private network, the IP range, and the subnet mask.

While it’s selected, I go to the text section on the right. I position it to the left and the top of the text area.

I resize it and place it at the top left in the VPC area.

Now I add the internet gateway by searching for it in the search bar in the top right.

I place it in the cloud provider and outside of the VPC.

Now I go back to the search bar and search for “cloud”.

I write on it “Internet”.

I link it to the internet gateway.

I now link the internet gateway to the VPC.

I now add computers, and I click on the laptop.

It‘s the SOC analyst’s laptop, and I link it to the internet.

I added the arrow to indicate that it will be used to connect to the Elastic/Kibana server via the web GUI.

I can duplicate the laptop using CTRL + D. It will be the attacker’s laptop.

I changed its color to red.

I add to the name of the C2 server, and since it’s a tool of the attacker, I also change its color to red.

I link both of the attacker’s tools to the internet.

I will export it to the PDF format. I have to select everything with CTRL + A.

I go to “File” in the top menu, then “Export as” and “PDF…”.

Here, I need to check “Selection Only” to include all the selected elements. I pick “Fit to 1 by 1" to make sure it’s all on one page, and I click on “Export”.

I take out the .drawio of the name, then I click on “Save”. Leaving it doesn’t affect anything, but I like the file name to have one file extension.

This is the final result.

A reminder, you can save every few minutes with CTRL + S to make sure you don’t lose your progress, no matter what happens. I think it autosaves after the first save, but it has become a habit for me.

I will take a step back from the 30-day challenge to focus on the SC-200. My primary focus will be on learning to utilize Microsoft’s cybersecurity tools and posting extensive investigative reports on this platform.


메타데이터
post_id
f19b9e1df0ea
slug
day-1-30-day-mydfir-soc-analyst-challenge-f19b9e1df0ea
url
https://medium.com/@itszensden/day-1-30-day-mydfir-soc-analyst-challenge-f19b9e1df0ea
canonical_url
https://medium.com/@itszensden/day-1-30-day-mydfir-soc-analyst-challenge-f19b9e1df0ea
author_url
https://medium.com/@itszensden
status
ok
fetched_at
2026-07-14 15:00:07