Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

22 Commits
 
 
 
 

Repository files navigation

SOC Skills Roadmap

About This Repo

This repository documents my progression through a structured 7-project SOC skills roadmap. It picks up where the MyDFIR 30-Day SOC Analyst Challenge left off. The goal is to build verifiable, hands-on evidence across the core skills a Tier 2 SOC analyst needs: SIEM, forensics, log analysis, Active Directory, vulnerability management, and malware analysis.

Each project folder contains markdown write-ups for every sub-project, screenshots of key findings, and MITRE ATT&CK technique mappings where applicable. This is not theory. Everything here was built, tested, and documented.


Roadmap Overview

# Project Focus Area Duration Status
1 Splunk Projects SIEM Skills 2 weeks In Progress
2 Windows Forensics Windows Investigation 1.5 weeks Not Started
3 Log Analysis Windows Investigation 1 week Not Started
4 Active Directory Monitoring Enterprise Environment 2 weeks Not Started
5 Security Assessments Enterprise Environment 1 week Not Started
6 Vulnerability Management Advanced Skills 1 week Not Started
7 Malware Analysis Advanced Skills 2 weeks Not Started

Total duration: 11 weeks
Start date: June 2026
Target completion: August 2026


Project Breakdown

1. Splunk Projects (Weeks 1 and 2)

Covers log analysis across DNS, FTP, HTTP, SSH, tunneling, SMTP, and DHCP using Splunk as the SIEM platform.

2. Windows Forensics (Week 3 and first half of Week 4)

Covers event log investigation, registry analysis, file system forensics, browser artifacts, and deleted file recovery.

3. Log Analysis (Week 5 and second half of Week 4)

Covers JSON log correlation using jq and CyberChef.

4. Active Directory Monitoring (Weeks 6 and 7)

Covers AD lab setup, domain configuration, Sysmon and Splunk integration, and attack simulation including Kerberoasting and DCSync detection.

5. Security Assessments (Week 8)

Covers Nessus scans, risk assessment reports, and compliance checks.

6. Vulnerability Management (Week 9)

Covers the full vulnerability lifecycle: scan, prioritise, remediate, and verify.

7. Malware Analysis (Weeks 10 and 11)

Covers sandbox analysis, IOC extraction, and static analysis using REMnux and Any.run.


Documentation Standard

Every sub-project follows the same documentation approach used in the DFIR challenge repo:

  • One markdown file per sub-project
  • Screenshots of key findings included
  • MITRE ATT&CK technique mapped where applicable
  • README updated after each project is completed
  • One LinkedIn post published per completed project (not per sub-project)

Context

This roadmap is part of a broader NSS preparation strategy. I am targeting Stanbic Bank Ghana and MTN Ghana for National Service starting September 2026. Completing these 7 projects on top of the 21-day DFIR challenge builds a Tier 2 SOC analyst profile with documented, verifiable evidence. Most NSS candidates have theory. This is proof.


Last updated: June 2026

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors