This repository documents my progression through a structured 7-project SOC skills roadmap. It picks up where the MyDFIR 30-Day SOC Analyst Challenge left off. The goal is to build verifiable, hands-on evidence across the core skills a Tier 2 SOC analyst needs: SIEM, forensics, log analysis, Active Directory, vulnerability management, and malware analysis.
Each project folder contains markdown write-ups for every sub-project, screenshots of key findings, and MITRE ATT&CK technique mappings where applicable. This is not theory. Everything here was built, tested, and documented.
| # | Project | Focus Area | Duration | Status |
|---|---|---|---|---|
| 1 | Splunk Projects | SIEM Skills | 2 weeks | In Progress |
| 2 | Windows Forensics | Windows Investigation | 1.5 weeks | Not Started |
| 3 | Log Analysis | Windows Investigation | 1 week | Not Started |
| 4 | Active Directory Monitoring | Enterprise Environment | 2 weeks | Not Started |
| 5 | Security Assessments | Enterprise Environment | 1 week | Not Started |
| 6 | Vulnerability Management | Advanced Skills | 1 week | Not Started |
| 7 | Malware Analysis | Advanced Skills | 2 weeks | Not Started |
Total duration: 11 weeks
Start date: June 2026
Target completion: August 2026
Covers log analysis across DNS, FTP, HTTP, SSH, tunneling, SMTP, and DHCP using Splunk as the SIEM platform.
Covers event log investigation, registry analysis, file system forensics, browser artifacts, and deleted file recovery.
Covers JSON log correlation using jq and CyberChef.
Covers AD lab setup, domain configuration, Sysmon and Splunk integration, and attack simulation including Kerberoasting and DCSync detection.
Covers Nessus scans, risk assessment reports, and compliance checks.
Covers the full vulnerability lifecycle: scan, prioritise, remediate, and verify.
Covers sandbox analysis, IOC extraction, and static analysis using REMnux and Any.run.
Every sub-project follows the same documentation approach used in the DFIR challenge repo:
- One markdown file per sub-project
- Screenshots of key findings included
- MITRE ATT&CK technique mapped where applicable
- README updated after each project is completed
- One LinkedIn post published per completed project (not per sub-project)
This roadmap is part of a broader NSS preparation strategy. I am targeting Stanbic Bank Ghana and MTN Ghana for National Service starting September 2026. Completing these 7 projects on top of the 21-day DFIR challenge builds a Tier 2 SOC analyst profile with documented, verifiable evidence. Most NSS candidates have theory. This is proof.
Last updated: June 2026