tcpdump and Wireshark
The two use different filter languages, and distractors swap them. tcpdump takes Berkeley Packet Filter capture filters such as host 192.0.2.10 and port 53, with -i for the interface, -n to skip name resolution, -w to write a file and -r to read one. Wireshark display filters look like ip.addr == 192.0.2.10 && dns and only hide packets already captured (tcpdump manual, Wireshark filter reference).
Zeek
Zeek writes one log per protocol: conn.log for every connection with duration and byte counts, dns.log for queries and answers, and more. Long, regular connections in conn.log and odd query names in dns.log lead into DNS tunneling, DGA and fast flux.
SIEM, EDR and the rest of the stack
A SIEM correlates what other tools send it; EDR sees inside one host; XDR stitches endpoint, network, cloud and email together. The boundaries are drawn in SIEM vs SOAR vs EDR (and XDR, UEBA). Threat-intel platforms such as MISP and OpenCTI connect this objective to threat intelligence and hunting.
Files, encodings and lookups
strings pulls readable text out of a binary. CyberChef decodes layers (Base64, hex, XOR, URL encoding), and an obfuscated command in an exhibit is often one Base64 step from readable. MXToolbox reads a domain's MX, SPF and DMARC records, which settles whether a sender is authorized.
Scripting
You will read code more than write it. Recognize PowerShell queries such as Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} (failed logons), a Python loop over JSON events, and the shape of an EVTX record next to the same event in JSON. Which sources produce those records in the first place is covered in architecture and logging for security operations.