// personal roadmap
Your path to SOC Analyst
Work top to bottom. Finish beginner steps before moving on — that's the fastest route to job-ready.
> start here
Networking fundamentals (TCP/IP, DNS, OSI)
Every security role depends on understanding how traffic moves.
- 1beginnerFoundations — start here.
Learn: Networking fundamentals (TCP/IP, DNS, OSI)
Every security role depends on understanding how traffic moves.
Learn: Windows & Linux administration
You'll investigate and harden these systems daily.
Learn: Command line (Bash & PowerShell)
Core to triage, automation and forensics.
Learn: Security fundamentals (CIA triad, threats, controls)
The vocabulary employers expect in interviews.
Learn: Log analysis
Reading logs is the heart of detection work.
Learn: Documentation & ticketing
Clear write-ups make you trustworthy on a team.
Earn: CompTIA Security+
- 2intermediateTools and hands-on practice.
Learn: SIEM tools (Splunk, Sentinel, Elastic)
The primary tool for SOC and analyst roles.
Learn: IDS/IPS & firewalls
Understanding alerts from network defenses.
Learn: Packet analysis (Wireshark, tcpdump)
Confirms what actually happened on the wire.
Learn: MITRE ATT&CK framework
Common language for attacker behavior.
Learn: EDR tools (CrowdStrike, Defender)
Endpoint visibility for detection and response.
Earn: Splunk Core Certified User
Earn: Blue Team Level 1 (BTL1)
- 3advancedSpecialize and stand out.
Learn: Threat hunting
Proactively finding attackers who evaded alerts.
Earn: GIAC GCIA
Already have some of these? Update your checklist.