فقط روی مباحثی تمرکز کن که در تحلیل Alertها، بررسی Logها و پاسخ اولیه به Incidentها استفاده میشن.
🌐 Networking
مدل OSI و TCP/IP
IP Addressing و Subnetting
DNS، DHCP، ARP
TCP و UDP
HTTP/HTTPS
SMTP، SMB، RDP، SSH
VPN، NAT
Firewall و Proxy
🖥️ Windows & Active Directory
ساختار ویندوز
Process و Service
Registry
Event Viewer
Task Scheduler
User و Group
NTFS Permission
Active Directory
OU و GPO
Kerberos و NTLM
PowerShell (مقدماتی)
🐧 Linux
ساختار فایلها
Permissionها
دستورات مهم: ls cd grep find ps top journalctl systemctl
مدیریت سرویسها
SSH
Bash (مقدماتی)
🔒 Security Fundamentals
CIA
AAA
Authentication & Authorization
Malware
انواع حملات
Cryptography
Hash و Encryption
PKI
Firewall
IDS/IPS
WAF
SIEM
EDR
MITRE ATT&CK
📊 Log Analysis & SIEM
ساختار Logها
Windows Event Log
Sysmon
Query نویسی
Dashboard
Alert
Correlation Rule
تحلیل Eventها
Timeline
IOC
🛡️ Endpoint Security
EDR
Microsoft Defender
Sysmon
Process Tree
Parent / Child Process
Command Line
File Hash
Persistence
LOLBins
🚨 Incident Response & Threat Intelligence
مراحل Incident Response
Triage و اولویتبندی Alertها
Containment
Escalation
IOC
Threat Intelligence Feed
VirusTotal
Sigma Rule
YARA (مقدماتی)
💡 نکته: هدف SOC Tier 1 این نیست که در همه این حوزهها متخصص باشی؛ بلکه باید به اندازهای یاد بگیری که بتونی لاگها رو تحلیل کنی، ارتباط بین Eventها را متوجه بشی و درباره یک Alert تصمیم درستی بگیری.
@Socroot