SOC Roadmap 🌐🔐
├── 0. Fundamentals
│ ├── Networking Basics
│ │ ├── OSI & TCP/IP Models
│ │ ├── IP Addressing, Subnetting
│ │ └── Protocols: HTTP, DNS, FTP, etc.
│ ├── Operating Systems
│ │ ├── Windows Internals
│ │ └── Linux Command Line & File System
│ └── Cybersecurity Basics
│ ├── CIA Triad (Confidentiality, Integrity, Availability)
│ ├── Threats & Vulnerabilities
│ └── Security Controls & Defense-in-Depth
├── 1. SOC Concepts & Roles
│ ├── What is a SOC?
│ ├── SOC Analyst Tiers (L1, L2, L3)
│ └── Incident Response Lifecycle
├── 2. Tools & Technologies
│ ├── SIEM Platforms
│ │ ├── Splunk, QRadar, ELK Stack
│ │ └── Log Analysis & Alerting
│ ├── EDR & XDR
│ │ ├── CrowdStrike, SentinelOne
│ │ └── Endpoint Monitoring
│ └── Threat Intelligence Platforms
│ ├── MISP, VirusTotal, AbuseIPDB
│ └── IOC (Indicators of Compromise) Analysis
├── 3. Log Analysis & Monitoring
│ ├── Windows Event Logs
│ ├── Syslog & Linux Logs
│ ├── Firewall & IDS/IPS Logs
│ └── Correlation & Alert Tuning
├── 4. Incident Response & Investigation
│ ├── Detection & Triage
│ ├── Containment, Eradication, Recovery
│ ├── Root Cause Analysis
│ └── Reporting & Documentation
├── 5. Threat Hunting & Forensics
│ ├── MITRE ATT&CK Framework
│ ├── Behavioral Analysis
│ ├── Memory & Disk Forensics
│ └── Malware Analysis Basics
├── 6. Soft Skills & Documentation
│ ├── Communication & Reporting
│ ├── Ticketing Systems (e.g., ServiceNow)
│ └── Collaboration with Blue/Red Teams
├── 7. Certifications & Career Growth
│ ├── Entry-Level: Security+, CySA+
│ ├── Intermediate: CEH, GCIA
│ └── Advanced: CISSP, GCIH, OSCP
نقشه راه SOC 🚨