π₯ The most comprehensive, production-ready SOC analyst training program on GitHub. Bridges foundational skills β automation mastery β offensive-defensive expertise β CISO-path thinking.
π Splunk SIEM β 8 Dashboard Hands-On Project SSH Brute-Force β’ Web Traffic β’ DNS β’ FTP β’ SMTP β’ DHCP β’ Tunnel β’ AWS GuardDuty
8,701 sample eventsΒ·SPL queriesΒ·Importable XMLΒ·MITRE ATT&CK mapped
π½ Click to expand
By 2026, cybercrime is a $20 trillion economy. The average data breach costs $4.88 million. Attack windows have collapsed from weeks to hours.
π¨ Traditional SOC analysts are obsolete. The future belongs to automation architects and CISO-path thinkers.
This program trains you for the new reality:
| 2026 Reality | What It Means |
|---|---|
| π€ AI agents handle 90%+ of routine triage | You supervise AI, not manually triage |
| π€ Human-agent teaming is baseline | You architect collaborative workflows |
| βοΈ SOAR orchestration is mandatory | You design automated response chains |
| βοΈ Cloud-native, identity-first security | You investigate across AWS/Azure/GCP |
| π― Intelligence-driven operations | You build ML-powered threat intel pipelines |
| π£ Purple team validation is expected | You attack AND defend β the CISO mindset |
| Document | Purpose | β±οΈ Read Time |
|---|---|---|
| π QUICK-START-GUIDE.md | Week 1 action plan, platform setup | 20 min |
| πΊοΈ SOC-Analyst-Roadmap.md | Original master plan (Projects 1-6) | 10 min |
| π 2026-Automation-First-Roadmap.md | Future-state vision (AI, SOAR, cloud, CISO-path) | 40 min |
| π INTEGRATION-GUIDE.md | How everything fits together | 35 min |
| Category | Projects | Status |
|---|---|---|
| π’ Foundation (Manual Skills) | P1-P6 | β Complete |
| π‘ Automation & Orchestration | P7-P8 | β Complete |
| π΅ AI & Emerging Tech | P9-P10 | β NEW β Complete |
| π΄ Offensive-Defensive Mastery | P11-P14 | β NEW β Complete |
Every template includes:
- β Day-by-day execution plan with real commands & code
- β Evidence capture guidelines
- β 3 resume bullet versions (CISO-path aligned)
- β STAR method interview answers
- β Skills developed checklist
- β Common mistakes to avoid
- β Quantifiable metrics & outcomes
Step 1οΈβ£ β Read the Quick Start Guide
cat QUICK-START-GUIDE.mdStep 2οΈβ£ β Create Platform Accounts (All Free)
| Platform | Purpose | Link |
|---|---|---|
| π΅ LetsDefend | SOC monitoring labs | letsdefend.io |
| π’ TryHackMe | SIEM & IR labs | tryhackme.com |
| π‘ CyberDefenders | Blue team CTFs | cyberdefenders.org |
Step 3οΈβ£ β Start Project 1
cat templates/Project-1-Template.mdπ― This Week: Triage your first 20 security alerts!
π― Goal: Entry-level SOC Analyst Tier-1 job
| Detail | Value |
|---|---|
| π Projects | 1, 2, 3, 7 |
| π Resume Bullets | 9-12 |
| π Portfolio Projects | 4 |
| πΌ Start Applying | Week 10 |
π― Goal: Mid-level SOC Analyst / Detection Engineer
| Detail | Value |
|---|---|
| π Projects | 1-7 (all foundation + SOAR) |
| π Resume Bullets | 15-18 |
| π Portfolio Projects | 7 + GitHub detection repo |
| πΌ Start Applying | Week 16 |
π― Goal: AI SOC Engineer / Tier 4 Orchestrator
| Detail | Value |
|---|---|
| π Projects | 1-10 (full automation suite) |
| π Resume Bullets | 20+ |
| π Portfolio | ML models, STIX bundles, PQC assessment |
| πΌ Start Applying | Week 20+ |
π― Goal: Senior Security Engineer β CISO Track
| Detail | Value |
|---|---|
| π Projects | 1-14 (complete mastery) |
| π Resume Bullets | 42+ CISO-aligned bullets |
| π Portfolio | AD attacks, cloud forensics, APT emulation, YARA rules |
| πΌ Target Roles | Security Architect, Staff SecEng, CISO-track |
π‘ Build manual investigation skills before automating.
| # | Project | Platform | β±οΈ Duration | π Difficulty | π Key Skills |
|---|---|---|---|---|---|
| 1 | π Live SOC Monitoring | LetsDefend | 2-3 weeks | π’ Beginner | Alert triage, log analysis |
| 2 | π§ Phishing Email Analysis | CyberDefenders | 1-2 weeks | π’ Beginner-Int | Email forensics, IOC extraction |
| 3 | π₯οΈ Incident Response (SIEM) | TryHackMe | 2-3 weeks | π‘ Intermediate | Splunk/Elastic, MITRE ATT&CK |
| 4 | π Ransomware Forensics | CyberDefenders | 2 weeks | π‘ Int-Advanced | Memory/PCAP analysis |
| 5 | π― Threat Hunting | TryHackMe | 2-3 weeks | π‘ Int-Advanced | Hypothesis-driven hunting |
| 6 | βοΈ Detection Engineering | Home Lab | 2-3 weeks | π΄ Advanced | Sigma rules, GitHub publication |
β‘ 2026 automation-first skills β SOAR orchestration & ML-powered TI.
| # | Project | Platform | β±οΈ Duration | π Difficulty | π Key Skills |
|---|---|---|---|---|---|
| 7 | π€ Automated Phishing Responder | Wazuh + Shuffle + TheHive | 2-3 weeks | π΄ Advanced | SOAR playbooks, API integration |
| 8 | π§ Automated Threat Intel Platform | MISP + OpenCTI + Cortex + ML | 3-4 weeks | π΄ Enterprise | ML filtering, STIX/TAXII, auto-detection |
π Project 8 Highlights:
- π€ ML model (89% accuracy) filters 10,000 IOCs β 50 actionable
- β‘ Intelligence β Detection time: 5 minutes (vs. 5 days manual)
- π― Automated Sigma rule generation + SIEM deployment
- π 15+ threat intelligence sources integrated
π§ͺ Next-generation capabilities β AI agents & quantum-safe cryptography.
| # | Project | Platform | β±οΈ Duration | π Difficulty | π Key Skills |
|---|---|---|---|---|---|
| 9 | π§ AI-Assisted Threat Hunting | Jupyter + LLM API + Splunk | 2-3 weeks | π΄ Advanced | AI supervision, prompt engineering, STIX 2.1 |
| 10 | π Post-Quantum Cryptography | OpenSSL + liboqs + Lab | 2 weeks | π΄ Advanced | NIST PQC, hybrid TLS, crypto inventory |
π Project 9 Highlights:
- π€ LLM agent performs autonomous log analysis in Jupyter
- π Hunt cycle time: 45 minutes (vs. 8 hours manual β 91% faster)
- π‘οΈ AI hallucination validation protocol built-in
- π¦ Automated STIX 2.1 intelligence bundle generation
π Project 10 Highlights:
- π¬ Inventory 200+ cryptographic implementations
- π Deploy hybrid TLS (classical + ML-KEM-768)
- π 36-month migration roadmap with cost analysis
- π’ Executive briefing β board-level risk communication
βοΈ CISO-path projects β attack, defend, and lead. The skills that separate elite security leaders.
| # | Project | Platform | β±οΈ Duration | π Difficulty | π Key Skills |
|---|---|---|---|---|---|
| 11 | π° AD Attack & Defense Lab | Home Lab + BloodHound + Impacket | 3 weeks | π΄ Advanced | Kerberoasting, DCSync, PtH, Golden Ticket + detection |
| 12 | βοΈ Cloud Security Investigation | AWS + Azure + Prowler | 3 weeks | π΄ Advanced | CloudTrail forensics, Sentinel KQL, PIM abuse |
| 13 | π£ Purple Team Exercise | ATT&CK Navigator + Atomic Red Team | 2 weeks | π΄ Advanced | APT emulation, full kill chain, coverage matrix |
| 14 | π¦ Malware Reverse Engineering | FlareVM + Any.Run + Wireshark | 2 weeks | π΄ Advanced | Static/dynamic analysis, YARA rules, C2 analysis |
π Project 11 Highlights:
- π° Deploy 2,500+ user AD with BadBlood vulnerabilities
- βοΈ Execute 6 AD attacks + build Sigma detection for each
- πΊοΈ BloodHound attack path analysis β 0 paths to Domain Admin
- π 100% detection coverage, <5 min MTTD
π Project 13 Highlights:
- π Reproduce real APT campaign (Scattered Spider)
- π΄π΅ Red side attacks + Blue side detects EVERY step
- πΊοΈ ATT&CK Navigator heatmap β 100% coverage
- π 12 techniques, 2.1-min average MTTD
π Project 14 Highlights:
- π¬ Static analysis: PEStudio, FLOSS, strings extraction
- π₯ Dynamic analysis: Any.Run sandbox, behavioral monitoring
- π Network analysis: Wireshark C2 traffic decoding
- βοΈ Write 5+ YARA rules with 95% detection, 0% false positives
| Category | Tools |
|---|---|
| π Training | LetsDefend β’ TryHackMe β’ CyberDefenders |
| π SIEM/EDR | Splunk Free β’ Elastic Stack β’ Wazuh |
| βοΈ SOAR | Shuffle β’ TheHive β’ Cortex |
| π§ Threat Intel | MISP β’ OpenCTI β’ AlienVault OTX |
| π Detection | Sigma β’ YARA β’ Suricata |
| π€ AI/ML | Python scikit-learn β’ Jupyter β’ OpenAI/Claude APIs |
| βοΈ Offensive | Impacket β’ Mimikatz β’ BloodHound β’ Atomic Red Team |
| π¬ Malware Analysis | FlareVM β’ Any.Run β’ PEStudio β’ Wireshark |
| βοΈ Cloud Security | AWS CloudTrail β’ Azure Sentinel β’ Prowler |
| π Crypto | OpenSSL 3.x β’ liboqs β’ oqs-provider |
| Week | π Milestone | πΌ Job Readiness |
|---|---|---|
| 8-10 | Projects 1-3 complete | β Entry-level SOC Analyst Tier-1 |
| 12-16 | Projects 1-7 complete | β Mid-level SOC / Detection Analyst |
| 20-24 | Projects 1-10 + certs | β AI SOC Engineer, Tier 4 Orchestrator |
| 28-40 | Projects 1-14 complete | π Security Architect β CISO Path |
β Before (Generic):
β’ Studied cybersecurity fundamentals
β’ Completed online courses
β After This Program:
β’ Monitored and triaged 150+ security alerts, achieving 92% TP/FP accuracy
β’ Architected SOAR pipeline reducing MTTC from 45 minutes to 3 minutes
β’ Built ML-powered TIP processing 12,500 IOCs/day with 89% accuracy
β’ Led purple team exercise emulating APT campaign with 100% detection coverage
β’ Analyzed 10+ malware samples, authoring YARA rules with 95% detection rate
β’ Conducted multi-cloud security investigations across AWS and Azure
| Candidate Type | What They Have | Your Advantage |
|---|---|---|
| π Average | Courses only | You have 14 hands-on projects |
| π Good | 2-3 basic projects | You have SOAR + ML automation |
| π Top 10% | SOAR automation | You have purple team + cloud + RE |
| π Top 1% | β YOU | Full-stack security + CISO-path π |
| Level | Certifications | When |
|---|---|---|
| π’ Entry | CompTIA Security+ β’ AWS Cloud Practitioner | After P1-P3 |
| π‘ Intermediate | GSEC β’ AZ-500 (Azure Security) β’ AWS Security Specialty | After P1-P7 |
| π΄ Advanced | SEC545 (GenAI Security) β’ SEC598 (AI SOC) β’ AI-102 | After P1-P10 |
| π Elite | OSCP β’ CRTO β’ GCDA β’ CISSP | After P1-P14 |
π‘ Pro Tip: Projects > Certifications in the 2026 market. Build first, certify second.
soc-roadmap-2026/
βββ π README.md β You are here
βββ π QUICK-START-GUIDE.md β START HERE
βββ πΊοΈ SOC-Analyst-Roadmap.md
βββ π€ 2026-Automation-First-Roadmap.md
βββ π INTEGRATION-GUIDE.md
βββ π templates/
β βββ π’ Project-1-Template.md (Live SOC Monitoring)
β βββ π’ Project-2-Template.md (Phishing Analysis)
β βββ π’ Project-3-Template.md (Incident Response)
β βββ π’ Project-4-Template.md (Ransomware Forensics)
β βββ π’ Project-5-Template.md (Threat Hunting)
β βββ π’ Project-6-Template.md (Detection Engineering)
β βββ π‘ Project-7-Template.md (SOAR Automation)
β βββ π‘ Project-8-Template.md (ML Threat Intel) π
β βββ π΅ Project-9-Template.md (AI Threat Hunting) β NEW
β βββ π΅ Project-10-Template.md (Post-Quantum Crypto) β NEW
β βββ π΄ Project-11-Template.md (AD Attack & Defense) β NEW
β βββ π΄ Project-12-Template.md (Cloud Security) β NEW
β βββ π΄ Project-13-Template.md (Purple Team) β NEW
β βββ π΄ Project-14-Template.md (Malware RE) β NEW
βββ π LICENSE
- β Star this repository
- π Read QUICK-START-GUIDE.md
- π Create accounts (LetsDefend, TryHackMe, CyberDefenders)
- π Open Project-1-Template.md
- π― Complete Day 1-7 tasks (first 20 alerts)
- π Start your triage log
- β Complete Projects 1-3
- π Update resume with 6-9 SOC bullets
- πΌ Start applying for SOC Analyst jobs
- βοΈ Complete Projects 11-14
- π 42+ CISO-aligned resume bullets
- π― Target: Security Architect / Senior SecEng roles
This is a solo training program, but contributions are welcome!
| Type | How |
|---|---|
| π Bug Reports | Report issues or unclear instructions |
| π‘ Ideas | Suggest additional project ideas |
| π Success Stories | Share your wins! |
| π Pull Requests | Submit corrections & improvements |
Guidelines:
- Follow existing template structure
- Keep content actionable (not theoretical)
- Test technical steps before submitting
π’ We provide FREE & Premium IT learning resources β cybersecurity PDFs, AI tools, coding projects, cloud computing materials, networking labs, desktop support notes, interview preparation content, practical tutorials, and career-focused tech education to help students and beginners build real-world IT skills.
| π What You Get | π― Topics Covered |
|---|---|
| π Cybersecurity PDFs & Labs | Pentesting, SOC, Blue Team, Red Team |
| π€ AI Tools & Resources | ChatGPT, Claude, AI automation workflows |
| π» Coding Projects | Python, JavaScript, full-stack development |
| βοΈ Cloud Computing Materials | AWS, Azure, GCP labs & study guides |
| π Networking Labs | CCNA, CompTIA Network+, packet analysis |
| π₯οΈ Desktop Support Notes | IT support, helpdesk, troubleshooting |
| π Interview Preparation | Resume tips, STAR answers, mock Q&A |
| π Certification Materials | Security+, CySA+, AZ-500, AWS SAA |
| π οΈ Practical Tutorials | Hands-on labs, real-world projects |
| π Career-Focused Education | Job hunting, portfolio building, skills roadmaps |
Whether you want to learn cybersecurity, networking, cloud computing, coding, system administration, AI tools, or prepare for IT jobs and certifications β this channel shares valuable educational content, practical labs, and premium study materials for tech learners.
This project is licensed under the MIT License β see LICENSE for details.
β Use for personal learning β’ β Share with others β’ β Modify and adapt β’ β Use in portfolios
What you have: β Complete training program (250,000+ words) β’ β 14 project blueprints (ALL complete) β 42+ CISO-path resume bullets β’ β Day-by-day execution plans β’ β STAR interview prep
What you need: β° Consistency (10 hrs/week) β’ π Execution (start, don't read) β’ β³ Patience (8-40 weeks)
Made with π by security professionals, for future CISOs




