What problem does it solve? Preparing for the OffSec SOC-200/OSDA exam requires mastering log-based detection across Windows Event Logs, Sysmon, PowerShell logging, and ELK SIEM, but the material spans 19 modules and hundreds of event IDs. This Skill organizes that knowledge into a structured detection workflow so you can reconstruct multi-phase attacks from logs and write a passing exam report. ## Core Features & Use Cases - Detection Reference Library: Deep-dive references for all 19 SOC-200 modules, Windows Event IDs, Sysmon events, PowerShell logging, and event-to-attack mappings (Kerberoasting, DCSync, Pass-the-Hash, AMSI bypass). - KQL & OSQuery Guidance: Ready-to-use Kibana Query Language detection patterns and OSQuery SQL statements for active verification of services, listening ports, and processes. - Exam Strategy & Reporting: Challenge lab methodology, 24-hour time management plan, anti-patterns checklist, and a structured report template covering per-phase analysis, IOCs, and MITRE ATT&CK mapping. - Use Case: During the OSDA exam, you find a suspicious service installation. Use this Skill to look up Event ID 7045 detection patterns, build a KQL query to follow the PID chain, verify with OSQuery, and document the phase in the report template. ## Quick Start Ask the agent to help you build a KQL detection query for lateral movement via RDP logons using the SOC-200 skill.