The request for a "soc.4.mp4" write-up likely refers to a specific exercise or module from a cybersecurity training platform, such as or LetsDefend . While several labs involve SOC analyst levels 1 through 4, "soc.4.mp4" is not a standard, singular lab title.

If the "mp4" file contained hidden macros or shellcode, explain how you extracted the true command (e.g., XOR-based obfuscation ). Outcome (Findings & Recommendations)

Recommendations for future prevention, like patching specific vulnerabilities .

Note the initial risk level assigned to the alert. Tools (Platforms Used)

State whether the alert was a legitimate threat.

If you are referring to a specific lab like or TryHackMe's Elastic SOC Lab , please provide the platform name or exact lab title so I can give you the precise answers and walkthrough steps.

Checking traffic for communication with known malicious IPs or domains.