// personal roadmap

Your path to SOC Analyst

Work top to bottom. Finish beginner steps before moving on — that's the fastest route to job-ready.

> start here

Networking fundamentals (TCP/IP, DNS, OSI)

Every security role depends on understanding how traffic moves.

  1. 1
    beginnerFoundations — start here.
    • Learn: Networking fundamentals (TCP/IP, DNS, OSI)

      Every security role depends on understanding how traffic moves.

    • Learn: Windows & Linux administration

      You'll investigate and harden these systems daily.

    • Learn: Command line (Bash & PowerShell)

      Core to triage, automation and forensics.

    • Learn: Security fundamentals (CIA triad, threats, controls)

      The vocabulary employers expect in interviews.

    • Learn: Log analysis

      Reading logs is the heart of detection work.

    • Learn: Documentation & ticketing

      Clear write-ups make you trustworthy on a team.

    • Earn: CompTIA Security+

  2. 2
    intermediateTools and hands-on practice.
    • Learn: SIEM tools (Splunk, Sentinel, Elastic)

      The primary tool for SOC and analyst roles.

    • Learn: IDS/IPS & firewalls

      Understanding alerts from network defenses.

    • Learn: Packet analysis (Wireshark, tcpdump)

      Confirms what actually happened on the wire.

    • Learn: MITRE ATT&CK framework

      Common language for attacker behavior.

    • Learn: EDR tools (CrowdStrike, Defender)

      Endpoint visibility for detection and response.

    • Earn: Splunk Core Certified User

    • Earn: Blue Team Level 1 (BTL1)

  3. 3
    advancedSpecialize and stand out.
    • Learn: Threat hunting

      Proactively finding attackers who evaded alerts.

    • Earn: GIAC GCIA

Already have some of these? Update your checklist.