A practical, hands-on learning journey focused on Security Operations, Blue Team operations, networking, Linux, SIEM, IDS/IPS, EDR and incident investigation.
Build practical SOC Analyst skills through:
- Security monitoring
- Log analysis
- Network security
- Linux
- Windows security
- IDS/IPS
- SIEM
- Threat intelligence
- EDR
- Incident investigation
Each topic follows:
Theory ↓ Practical Lab ↓ Evidence ↓ Investigation ↓ Documentation ↓ Interview Preparation
| Day | Topic | Status |
|---|---|---|
| 01 | SOC Fundamentals | ✅ Completed |
| 02 | Windows Event Logs & Authentication | 🔄 Next |
| 03 | Networking for SOC | ⏳ |
| 04 | Linux for SOC | ⏳ |
| 05 | Network Traffic Analysis & Wireshark | ⏳ |
| 06 | Snort IDS/IPS | ⏳ |
| 07 | Suricata IDS/IPS | ⏳ |
| 08 | SIEM Fundamentals | ⏳ |
| 09 | Splunk Hands-on | ⏳ |
| 10 | OSINT & Threat Intelligence | ⏳ |
| 11 | EDR & Endpoint Security | ⏳ |
| 12 | Incident Investigation | ⏳ |
| 13 | Detection & Alert Analysis | ⏳ |
| 14 | SOC Investigation Case Study | ⏳ |
- Windows Event Viewer
- Linux
- Snort
- Suricata
- Splunk
- Elastic Stack
- VirusTotal
- AbuseIPDB
- EDR platforms
- Wireshark
- Git & GitHub
All security testing and practical exercises are performed in controlled laboratory environments for educational purposes.