Skip to content

Repository files navigation


License: MIT Projects Content Status SOC Automation


Typing SVG


πŸ”₯ The most comprehensive, production-ready SOC analyst training program on GitHub. Bridges foundational skills β†’ automation mastery β†’ offensive-defensive expertise β†’ CISO-path thinking.


πŸ”₯ Featured Hands-On Project

Splunk Dashboard Project

πŸ“Š Splunk SIEM β€” 8 Dashboard Hands-On Project SSH Brute-Force β€’ Web Traffic β€’ DNS β€’ FTP β€’ SMTP β€’ DHCP β€’ Tunnel β€’ AWS GuardDuty 8,701 sample events Β· SPL queries Β· Importable XML Β· MITRE ATT&CK mapped



πŸ“‹ Table of Contents

πŸ”½ Click to expand

🎯 Overview

Cybersecurity animation

⚑ The SOC Landscape Has Changed Forever

By 2026, cybercrime is a $20 trillion economy. The average data breach costs $4.88 million. Attack windows have collapsed from weeks to hours.

🚨 Traditional SOC analysts are obsolete. The future belongs to automation architects and CISO-path thinkers.

This program trains you for the new reality:

2026 Reality What It Means
πŸ€– AI agents handle 90%+ of routine triage You supervise AI, not manually triage
🀝 Human-agent teaming is baseline You architect collaborative workflows
βš™οΈ SOAR orchestration is mandatory You design automated response chains
☁️ Cloud-native, identity-first security You investigate across AWS/Azure/GCP
🎯 Intelligence-driven operations You build ML-powered threat intel pipelines
🟣 Purple team validation is expected You attack AND defend β€” the CISO mindset


🎁 What You Get

πŸ—οΈ The Complete SOC Training Arsenal

πŸ“š Core Documents (250,000+ words)

Document Purpose ⏱️ Read Time
πŸ“– QUICK-START-GUIDE.md Week 1 action plan, platform setup 20 min
πŸ—ΊοΈ SOC-Analyst-Roadmap.md Original master plan (Projects 1-6) 10 min
πŸš€ 2026-Automation-First-Roadmap.md Future-state vision (AI, SOAR, cloud, CISO-path) 40 min
πŸ”— INTEGRATION-GUIDE.md How everything fits together 35 min

πŸ› οΈ 14 Project Templates β€” ALL Complete

Category Projects Status
🟒 Foundation (Manual Skills) P1-P6 βœ… Complete
🟑 Automation & Orchestration P7-P8 βœ… Complete
πŸ”΅ AI & Emerging Tech P9-P10 βœ… NEW β€” Complete
πŸ”΄ Offensive-Defensive Mastery P11-P14 βœ… NEW β€” Complete

Every template includes:

  • βœ… Day-by-day execution plan with real commands & code
  • βœ… Evidence capture guidelines
  • βœ… 3 resume bullet versions (CISO-path aligned)
  • βœ… STAR method interview answers
  • βœ… Skills developed checklist
  • βœ… Common mistakes to avoid
  • βœ… Quantifiable metrics & outcomes


πŸš€ Quick Start

Coding animation

🏁 Get Started in 3 Steps (30 minutes)

Step 1️⃣ β€” Read the Quick Start Guide

cat QUICK-START-GUIDE.md

Step 2️⃣ β€” Create Platform Accounts (All Free)

Platform Purpose Link
πŸ”΅ LetsDefend SOC monitoring labs letsdefend.io
🟒 TryHackMe SIEM & IR labs tryhackme.com
🟑 CyberDefenders Blue team CTFs cyberdefenders.org

Step 3️⃣ β€” Start Project 1

cat templates/Project-1-Template.md

🎯 This Week: Triage your first 20 security alerts!


πŸ›€οΈ Learning Paths

Path animation

πŸƒ Path A: Fast Track (10-12 weeks)

🎯 Goal: Entry-level SOC Analyst Tier-1 job

Detail Value
πŸ“‹ Projects 1, 2, 3, 7
πŸ“ Resume Bullets 9-12
πŸ“‚ Portfolio Projects 4
πŸ’Ό Start Applying Week 10

πŸ”§ Path B: Complete Professional (16-20 weeks)

🎯 Goal: Mid-level SOC Analyst / Detection Engineer

Detail Value
πŸ“‹ Projects 1-7 (all foundation + SOAR)
πŸ“ Resume Bullets 15-18
πŸ“‚ Portfolio Projects 7 + GitHub detection repo
πŸ’Ό Start Applying Week 16

πŸš€ Path C: Automation-First Leader (20-28 weeks)

🎯 Goal: AI SOC Engineer / Tier 4 Orchestrator

Detail Value
πŸ“‹ Projects 1-10 (full automation suite)
πŸ“ Resume Bullets 20+
πŸ“‚ Portfolio ML models, STIX bundles, PQC assessment
πŸ’Ό Start Applying Week 20+

πŸ‘‘ Path D: CISO-Path Elite (28-40 weeks) β€” ⭐ NEW

🎯 Goal: Senior Security Engineer β†’ CISO Track

Detail Value
πŸ“‹ Projects 1-14 (complete mastery)
πŸ“ Resume Bullets 42+ CISO-aligned bullets
πŸ“‚ Portfolio AD attacks, cloud forensics, APT emulation, YARA rules
πŸ’Ό Target Roles Security Architect, Staff SecEng, CISO-track


πŸ“‚ Project Portfolio

Shield animation

πŸ—‚οΈ 14 Projects β€’ 5 Phases β€’ Zero to CISO-Path

🟒 Foundation Projects (1-6)

πŸ’‘ Build manual investigation skills before automating.

# Project Platform ⏱️ Duration πŸ“Š Difficulty πŸ”‘ Key Skills
1 πŸ” Live SOC Monitoring LetsDefend 2-3 weeks 🟒 Beginner Alert triage, log analysis
2 πŸ“§ Phishing Email Analysis CyberDefenders 1-2 weeks 🟒 Beginner-Int Email forensics, IOC extraction
3 πŸ–₯️ Incident Response (SIEM) TryHackMe 2-3 weeks 🟑 Intermediate Splunk/Elastic, MITRE ATT&CK
4 πŸ” Ransomware Forensics CyberDefenders 2 weeks 🟑 Int-Advanced Memory/PCAP analysis
5 🎯 Threat Hunting TryHackMe 2-3 weeks 🟑 Int-Advanced Hypothesis-driven hunting
6 βš™οΈ Detection Engineering Home Lab 2-3 weeks πŸ”΄ Advanced Sigma rules, GitHub publication

🟑 Automation Projects (7-8)

⚑ 2026 automation-first skills β€” SOAR orchestration & ML-powered TI.

# Project Platform ⏱️ Duration πŸ“Š Difficulty πŸ”‘ Key Skills
7 πŸ€– Automated Phishing Responder Wazuh + Shuffle + TheHive 2-3 weeks πŸ”΄ Advanced SOAR playbooks, API integration
8 🧠 Automated Threat Intel Platform MISP + OpenCTI + Cortex + ML 3-4 weeks πŸ”΄ Enterprise ML filtering, STIX/TAXII, auto-detection

🌟 Project 8 Highlights:

  • πŸ€– ML model (89% accuracy) filters 10,000 IOCs β†’ 50 actionable
  • ⚑ Intelligence β†’ Detection time: 5 minutes (vs. 5 days manual)
  • 🎯 Automated Sigma rule generation + SIEM deployment
  • πŸ“Š 15+ threat intelligence sources integrated

πŸ”΅ AI & Emerging Tech (9-10) β€” ⭐ NEW

πŸ§ͺ Next-generation capabilities β€” AI agents & quantum-safe cryptography.

# Project Platform ⏱️ Duration πŸ“Š Difficulty πŸ”‘ Key Skills
9 🧠 AI-Assisted Threat Hunting Jupyter + LLM API + Splunk 2-3 weeks πŸ”΄ Advanced AI supervision, prompt engineering, STIX 2.1
10 πŸ” Post-Quantum Cryptography OpenSSL + liboqs + Lab 2 weeks πŸ”΄ Advanced NIST PQC, hybrid TLS, crypto inventory

🌟 Project 9 Highlights:

  • πŸ€– LLM agent performs autonomous log analysis in Jupyter
  • πŸ“Š Hunt cycle time: 45 minutes (vs. 8 hours manual β€” 91% faster)
  • πŸ›‘οΈ AI hallucination validation protocol built-in
  • πŸ“¦ Automated STIX 2.1 intelligence bundle generation

🌟 Project 10 Highlights:

  • πŸ”¬ Inventory 200+ cryptographic implementations
  • πŸ”’ Deploy hybrid TLS (classical + ML-KEM-768)
  • πŸ“‹ 36-month migration roadmap with cost analysis
  • 🏒 Executive briefing β€” board-level risk communication

πŸ”΄ Offensive-Defensive Mastery (11-14) β€” ⭐ NEW

βš”οΈ CISO-path projects β€” attack, defend, and lead. The skills that separate elite security leaders.

# Project Platform ⏱️ Duration πŸ“Š Difficulty πŸ”‘ Key Skills
11 🏰 AD Attack & Defense Lab Home Lab + BloodHound + Impacket 3 weeks πŸ”΄ Advanced Kerberoasting, DCSync, PtH, Golden Ticket + detection
12 ☁️ Cloud Security Investigation AWS + Azure + Prowler 3 weeks πŸ”΄ Advanced CloudTrail forensics, Sentinel KQL, PIM abuse
13 🟣 Purple Team Exercise ATT&CK Navigator + Atomic Red Team 2 weeks πŸ”΄ Advanced APT emulation, full kill chain, coverage matrix
14 🦠 Malware Reverse Engineering FlareVM + Any.Run + Wireshark 2 weeks πŸ”΄ Advanced Static/dynamic analysis, YARA rules, C2 analysis

🌟 Project 11 Highlights:

  • 🏰 Deploy 2,500+ user AD with BadBlood vulnerabilities
  • βš”οΈ Execute 6 AD attacks + build Sigma detection for each
  • πŸ—ΊοΈ BloodHound attack path analysis β†’ 0 paths to Domain Admin
  • πŸ“Š 100% detection coverage, <5 min MTTD

🌟 Project 13 Highlights:

  • 🎭 Reproduce real APT campaign (Scattered Spider)
  • πŸ”΄πŸ”΅ Red side attacks + Blue side detects EVERY step
  • πŸ—ΊοΈ ATT&CK Navigator heatmap β€” 100% coverage
  • πŸ“Š 12 techniques, 2.1-min average MTTD

🌟 Project 14 Highlights:

  • πŸ”¬ Static analysis: PEStudio, FLOSS, strings extraction
  • πŸ’₯ Dynamic analysis: Any.Run sandbox, behavioral monitoring
  • 🌐 Network analysis: Wireshark C2 traffic decoding
  • ✍️ Write 5+ YARA rules with 95% detection, 0% false positives


πŸ› οΈ Technology Stack

Tech Stack Icons

πŸ—οΈ Platforms (Free & Open-Source)

Category Tools
πŸŽ“ Training LetsDefend β€’ TryHackMe β€’ CyberDefenders
πŸ“Š SIEM/EDR Splunk Free β€’ Elastic Stack β€’ Wazuh
βš™οΈ SOAR Shuffle β€’ TheHive β€’ Cortex
🧠 Threat Intel MISP β€’ OpenCTI β€’ AlienVault OTX
πŸ” Detection Sigma β€’ YARA β€’ Suricata
πŸ€– AI/ML Python scikit-learn β€’ Jupyter β€’ OpenAI/Claude APIs
βš”οΈ Offensive Impacket β€’ Mimikatz β€’ BloodHound β€’ Atomic Red Team
πŸ”¬ Malware Analysis FlareVM β€’ Any.Run β€’ PEStudio β€’ Wireshark
☁️ Cloud Security AWS CloudTrail β€’ Azure Sentinel β€’ Prowler
πŸ” Crypto OpenSSL 3.x β€’ liboqs β€’ oqs-provider


πŸ“ˆ Career Outcomes

Success animation

πŸ“… Timeline Expectations

Week πŸ† Milestone πŸ’Ό Job Readiness
8-10 Projects 1-3 complete βœ… Entry-level SOC Analyst Tier-1
12-16 Projects 1-7 complete βœ… Mid-level SOC / Detection Analyst
20-24 Projects 1-10 + certs βœ… AI SOC Engineer, Tier 4 Orchestrator
28-40 Projects 1-14 complete πŸ‘‘ Security Architect β†’ CISO Path

πŸ“ Resume Transformation

❌ Before (Generic):

β€’ Studied cybersecurity fundamentals
β€’ Completed online courses

βœ… After This Program:

β€’ Monitored and triaged 150+ security alerts, achieving 92% TP/FP accuracy
β€’ Architected SOAR pipeline reducing MTTC from 45 minutes to 3 minutes
β€’ Built ML-powered TIP processing 12,500 IOCs/day with 89% accuracy
β€’ Led purple team exercise emulating APT campaign with 100% detection coverage
β€’ Analyzed 10+ malware samples, authoring YARA rules with 95% detection rate
β€’ Conducted multi-cloud security investigations across AWS and Azure

πŸ† Competitive Advantage

Candidate Type What They Have Your Advantage
😐 Average Courses only You have 14 hands-on projects
πŸ™‚ Good 2-3 basic projects You have SOAR + ML automation
😊 Top 10% SOAR automation You have purple team + cloud + RE
πŸ‘‘ Top 1% ← YOU Full-stack security + CISO-path πŸ†


πŸŽ“ Certifications (Optional)

Level Certifications When
🟒 Entry CompTIA Security+ β€’ AWS Cloud Practitioner After P1-P3
🟑 Intermediate GSEC β€’ AZ-500 (Azure Security) β€’ AWS Security Specialty After P1-P7
πŸ”΄ Advanced SEC545 (GenAI Security) β€’ SEC598 (AI SOC) β€’ AI-102 After P1-P10
πŸ‘‘ Elite OSCP β€’ CRTO β€’ GCDA β€’ CISSP After P1-P14

πŸ’‘ Pro Tip: Projects > Certifications in the 2026 market. Build first, certify second.


πŸ“ Repository Structure

soc-roadmap-2026/
β”œβ”€β”€ πŸ“– README.md                          ← You are here
β”œβ”€β”€ πŸš€ QUICK-START-GUIDE.md               ← START HERE
β”œβ”€β”€ πŸ—ΊοΈ SOC-Analyst-Roadmap.md
β”œβ”€β”€ πŸ€– 2026-Automation-First-Roadmap.md
β”œβ”€β”€ πŸ”— INTEGRATION-GUIDE.md
β”œβ”€β”€ πŸ“‚ templates/
β”‚   β”œβ”€β”€ 🟒 Project-1-Template.md          (Live SOC Monitoring)
β”‚   β”œβ”€β”€ 🟒 Project-2-Template.md          (Phishing Analysis)
β”‚   β”œβ”€β”€ 🟒 Project-3-Template.md          (Incident Response)
β”‚   β”œβ”€β”€ 🟒 Project-4-Template.md          (Ransomware Forensics)
β”‚   β”œβ”€β”€ 🟒 Project-5-Template.md          (Threat Hunting)
β”‚   β”œβ”€β”€ 🟒 Project-6-Template.md          (Detection Engineering)
β”‚   β”œβ”€β”€ 🟑 Project-7-Template.md          (SOAR Automation)
β”‚   β”œβ”€β”€ 🟑 Project-8-Template.md          (ML Threat Intel) πŸš€
β”‚   β”œβ”€β”€ πŸ”΅ Project-9-Template.md          (AI Threat Hunting) ⭐ NEW
β”‚   β”œβ”€β”€ πŸ”΅ Project-10-Template.md         (Post-Quantum Crypto) ⭐ NEW
β”‚   β”œβ”€β”€ πŸ”΄ Project-11-Template.md         (AD Attack & Defense) ⭐ NEW
β”‚   β”œβ”€β”€ πŸ”΄ Project-12-Template.md         (Cloud Security) ⭐ NEW
β”‚   β”œβ”€β”€ πŸ”΄ Project-13-Template.md         (Purple Team) ⭐ NEW
β”‚   └── πŸ”΄ Project-14-Template.md         (Malware RE) ⭐ NEW
└── πŸ“œ LICENSE


πŸš€ Getting Started

πŸ“… Today (30 minutes)

  1. ⭐ Star this repository
  2. πŸ“– Read QUICK-START-GUIDE.md
  3. πŸ” Create accounts (LetsDefend, TryHackMe, CyberDefenders)

πŸ“… This Week (10 hours)

  1. πŸ“‚ Open Project-1-Template.md
  2. 🎯 Complete Day 1-7 tasks (first 20 alerts)
  3. πŸ“ Start your triage log

πŸ“… Week 8-10

  1. βœ… Complete Projects 1-3
  2. πŸ“„ Update resume with 6-9 SOC bullets
  3. πŸ’Ό Start applying for SOC Analyst jobs

πŸ“… Week 28-40 (CISO Path)

  1. βš”οΈ Complete Projects 11-14
  2. πŸ‘‘ 42+ CISO-aligned resume bullets
  3. 🎯 Target: Security Architect / Senior SecEng roles

🀝 Contributing

This is a solo training program, but contributions are welcome!

Type How
πŸ› Bug Reports Report issues or unclear instructions
πŸ’‘ Ideas Suggest additional project ideas
πŸ“ Success Stories Share your wins!
πŸ”— Pull Requests Submit corrections & improvements

Guidelines:

  • Follow existing template structure
  • Keep content actionable (not theoretical)
  • Test technical steps before submitting


πŸ’¬ Join Our WhatsApp Community

WhatsApp Badge



πŸš€ FREE & Premium IT Learning Resources β€” All in One Channel

Join WhatsApp Channel



πŸ“’ We provide FREE & Premium IT learning resources β€” cybersecurity PDFs, AI tools, coding projects, cloud computing materials, networking labs, desktop support notes, interview preparation content, practical tutorials, and career-focused tech education to help students and beginners build real-world IT skills.

πŸ“š What You Get 🎯 Topics Covered
πŸ”’ Cybersecurity PDFs & Labs Pentesting, SOC, Blue Team, Red Team
πŸ€– AI Tools & Resources ChatGPT, Claude, AI automation workflows
πŸ’» Coding Projects Python, JavaScript, full-stack development
☁️ Cloud Computing Materials AWS, Azure, GCP labs & study guides
🌐 Networking Labs CCNA, CompTIA Network+, packet analysis
πŸ–₯️ Desktop Support Notes IT support, helpdesk, troubleshooting
πŸ“ Interview Preparation Resume tips, STAR answers, mock Q&A
πŸŽ“ Certification Materials Security+, CySA+, AZ-500, AWS SAA
πŸ› οΈ Practical Tutorials Hands-on labs, real-world projects
πŸ“ˆ Career-Focused Education Job hunting, portfolio building, skills roadmaps

Whether you want to learn cybersecurity, networking, cloud computing, coding, system administration, AI tools, or prepare for IT jobs and certifications β€” this channel shares valuable educational content, practical labs, and premium study materials for tech learners.




πŸ“œ License

This project is licensed under the MIT License β€” see LICENSE for details.

βœ… Use for personal learning β€’ βœ… Share with others β€’ βœ… Modify and adapt β€’ βœ… Use in portfolios


🎯 Final Thoughts

What you have: βœ… Complete training program (250,000+ words) β€’ βœ… 14 project blueprints (ALL complete) βœ… 42+ CISO-path resume bullets β€’ βœ… Day-by-day execution plans β€’ βœ… STAR interview prep

What you need: ⏰ Consistency (10 hrs/week) β€’ πŸš€ Execution (start, don't read) β€’ ⏳ Patience (8-40 weeks)


Typing SVG




Made with πŸ” by security professionals, for future CISOs


Profile Views

About

Complete SOC Analyst Training Roadmap 2026: 14 hands-on projects (SIEM, SOAR, TIP, ML) for automation-first defenders

Topics

Resources

Stars

146 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors