{ }< />( )[ ]=>::&&||
🌳 SKILL TREE

SOC Analyst

A roadmap for security operations: networking, logs, SIEM, alert triage, incident response, threat intelligence, detection rules, and SOC portfolio labs.

13Skills
0Done
0XP
0%
📘

Security and Networking Foundations

CORE

Build the base needed to understand alerts: networking, Windows/Linux basics, identity, malware, web attacks, and security controls.

📘

Networking and OS Logs

CORE

Understand TCP/IP, DNS, HTTP, Windows Event Logs, Linux auth logs, process activity, and endpoint telemetry.

📘

Common Attacks

CORE

Recognize phishing, brute force, suspicious PowerShell, malware beacons, web attacks, lateral movement, and data exfiltration.

📘

SIEM and Alert Triage

CORE

Use SIEM tools to search logs, validate alerts, enrich events, prioritize incidents, and write useful case notes.

📘

Log Search and Correlation

CORE

Search by host, user, IP, hash, process, URL, time window, event ID, and correlate across data sources.

📘

Case Notes and Escalation

CORE

Document evidence, impact, timeline, scope, false-positive reasons, next actions, and escalation paths.

📘

Practice: Suspicious Login Triage

⚡ ADV

Investigate login logs, IP reputation, impossible travel, MFA status, device history, and escalation notes.

📘

Detection Engineering and Incident Response

⚡ ADV

Move from reacting to alerts toward writing detections, tuning rules, hunting threats, and improving playbooks.

📘

Detection Rules

⚡ ADV

Write Sigma/YARA-style detections, tune noisy alerts, map to ATT&CK, and test with sample telemetry.

📘

Threat Hunting

⚡ ADV

Use hypotheses, indicators, baselines, timelines, ATT&CK techniques, and hunting reports.

📘

SOC Lab and Career Readiness

⚡ ADV

Build evidence of SOC skill with home labs, alert writeups, detection rules, reports, and interview stories.

📘

Home Lab

⚡ ADV

Run Security Onion, Splunk, Wazuh, sample logs, attack simulations, and incident response notebooks.

📘

Project: Alert Triage Portfolio

⚡ ADV

Analyze sample alerts, write case notes, build a timeline, classify severity, propose detection tuning, and publish a report.