0% found this document useful (0 votes)
83 views8 pages

Home SOC Lab Study Plan for Analysts

The document outlines a 3-month study plan for aspiring Tier 1 SOC Analysts, detailing a structured routine of 3 hours per day focusing on theory and practical labs. It covers essential topics such as cybersecurity fundamentals, operating systems, firewalls, incident response, and digital forensics, culminating in a final project to document a personal SOC lab setup. By the end of the program, participants will gain practical experience and a portfolio to enhance their job readiness in the cybersecurity field.

Uploaded by

0xshayansec
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
83 views8 pages

Home SOC Lab Study Plan for Analysts

The document outlines a 3-month study plan for aspiring Tier 1 SOC Analysts, detailing a structured routine of 3 hours per day focusing on theory and practical labs. It covers essential topics such as cybersecurity fundamentals, operating systems, firewalls, incident response, and digital forensics, culminating in a final project to document a personal SOC lab setup. By the end of the program, participants will gain practical experience and a portfolio to enhance their job readiness in the cybersecurity field.

Uploaded by

0xshayansec
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

3-Month SOC Analyst Study Plan

Duration: 12 Weeks (≈ 3 Months)​


Routine: 3 hours/day (1 hr theory + 2 hrs labs)​
Goal: Become job-ready for a Tier 1 SOC Analyst with a home SOC lab &
project portfolio.

Month 1: Cybersecurity & Network Foundations

Week 1: Cyber Security Fundamentals

Topics to Cover:

1.​ CIA Triad – Confidentiality, Integrity, Availability​

2.​ Networking:​

○​ OSI Model​

○​ TCP/IP Packet Headers​

3.​ Important Protocols & Concepts:​

○​ HTTP, HTTPS, DNS, FTP (Active/Passive), DHCP, ICMP, SMTP, POP3,


IMAP, Telnet, ARP, SNMP, RPC​

○​ HTTP methods & response codes​

○​ How DNS works & different records​

Labs:

●​ Capture HTTP & DNS packets in Wireshark.​

●​ Perform a DNS lookup using nslookup & dig.​

●​ Trace TCP 3-way handshake using Wireshark.​


Outcome:​
Understand network flow, protocols, and packet structures—crucial for SOC log
analysis.

Week 2: Operating Systems for SOC

Topics to Cover:

1.​ Linux & Windows Basics:​

○​ Directory structure & navigation​

○​ File system & file permissions​

○​ Editing files (nano, vim, gedit)​

○​ Network settings (DHCP → Static)​

2.​ Virtualization Tools: VMware, VirtualBox installation​

Labs:

●​ Install Kali Linux on VirtualBox/VMware.​

●​ Change file permissions using chmod and observe results.​

●​ Configure Static IP on Linux.​

●​ Explore Windows Event Viewer and identify security logs.​

Outcome:​
Ability to navigate & configure OS, a core SOC skill for log analysis.

Week 3: Firewalls, IDS & IPS

Topics to Cover:

1.​ Firewalls: Stateful, NextGen, WAF​

2.​ IDS vs IPS Concepts​

3.​ SOC Tools Overview:​


○​ Commercial: Checkpoint, Cisco ASA, Palo Alto, Fortinet​

○​ Open Source: pfSense, Security Onion (with Suricata & Zeek), Snort​

Labs:

●​ Deploy pfSense VM and set basic firewall rules.​

●​ Install Snort or Suricata for IDS and generate alerts.​

●​ Simulate ping flood / port scan to trigger IDS alerts.​

Mini Project:​
Export firewall logs & document a blocked traffic attempt.

Week 4: Vulnerability Management

Topics to Cover:

1.​ Vulnerability Scanning & Assessment​

2.​ Risk Assessment & Prioritization (Remediation, Mitigation, Acceptance)​

3.​ Continuous Vulnerability Management Process​

4.​ Tools: Nmap, OpenVAS/GVM, Tenable, Qualys, Rapid7​

Labs:

●​ Perform a network scan with Nmap.​

●​ Install & run OpenVAS to scan a VM.​

●​ Analyze vulnerabilities & prioritize remediation.​

Mini Project:​
Create a Vulnerability Assessment Report with risk ratings.

Month 2: SOC Operations & Threat Handling


Week 5: SIEM & Incident Response Basics

Topics to Cover:

1.​ Incident Response Lifecycle – Detection → Containment → Recovery​

2.​ Incident Response Frameworks: SANS, NIST​

3.​ SIEM Overview & Role in SOC​

Labs:

●​ Install Wazuh SIEM in a VM.​

●​ Connect Kali Linux agent to Wazuh.​

●​ Trigger alerts by performing:​

○​ Wrong SSH logins​

○​ Nmap port scans​

Outcome:​
Understand alert generation & log collection in a real SIEM.

Week 6: Threat Hunting & IR Playbooks

Topics to Cover:

1.​ MITRE ATT&CK Framework​

2.​ IoC & TTP Identification​

3.​ Incident Prioritization & Threat Triage​

4.​ IR Playbooks & Automation (Slack, MS Teams, ServiceNow)​

Labs:

●​ Analyze Wazuh logs for failed SSH brute force.​


●​ Create a playbook for brute-force attack response.​

●​ Document IoCs from lab activities.​

Mini Project:​
Prepare a full incident report with detection → containment steps.

Week 7: Phishing Analysis

Topics to Cover:

1.​ Types of Phishing: Email, Spear, Whaling, Smishing, Angler​

2.​ Email Header & URL Analysis​

3.​ Domain Reputation & WHOIS Lookup​

4.​ Tools: VirusTotal, [Link], IBM X-Force, CheckPhish​

Labs:

●​ Analyze sample phishing emails.​

●​ Perform WHOIS & IP/URL reputation checks.​

●​ Identify phishing techniques from real headers.​

Mini Project:​
Generate a Phishing Investigation Report.

Week 8: Malware Analysis (Basic)

Topics to Cover:

1.​ How Malware Works & Objectives​

2.​ Static vs Dynamic Analysis​

3.​ Sandboxing & Packers​

4.​ Tools: PeStudio, Process Monitor, ProcDot, AnyRun, Wireshark​


Labs:

●​ Perform static analysis with PeStudio.​

●​ Submit sample to AnyRun for dynamic analysis.​

●​ Observe network activity in Wireshark.​

Mini Project:​
Document the behavior of a malware sample.

Month 3: Advanced SOC, Forensics & Job-Readiness

Week 9: Digital Forensics Basics

Topics to Cover:

1.​ Collecting & Analyzing Network Evidence: Firewall, Proxy, NetFlow, Tcpdump​

2.​ Host-Based Evidence: RAM/ROM, System Storage​

3.​ Forensic Case Documentation​

4.​ Tools: Autopsy, FTK, Wireshark, Volatility, Registry Viewer​

Labs:

●​ Capture traffic with tcpdump & Wireshark.​

●​ Perform memory forensics with Volatility.​

●​ Recover deleted files using Autopsy.​

Outcome:​
Able to investigate security breaches & preserve evidence.

Week 10: Security Compliance

Topics to Cover:
1.​ Regulations & Frameworks: PCI DSS, HIPAA, GDPR, SOX, ISO 27001, NIST CSF​

2.​ SOC Alignment with Compliance​

Labs:

●​ Map SOC processes to ISO 27001/NIST CSF.​

●​ Identify potential compliance gaps for a fictional company.​

Outcome:​
Understand SOC’s role in governance and compliance.

Week 11: SOC Simulation Project

Activities:

●​ Simulate attacks:​

○​ Port Scan (Nmap)​

○​ SSH Brute Force​

○​ Sample Phishing Email​

●​ Detect & Analyze in:​

○​ Wazuh / Security Onion / IDS logs​

●​ Collect logs & perform forensics:​

○​ Firewall logs​

○​ SIEM alerts​

○​ IDS/IPS events​

Mini Project:​
Produce a complete SOC Incident Report as a case study.

Week 12: Job Preparation & Portfolio Building


Tasks:

1.​ Consolidate all lab reports, dashboards, and incident reports.​

2.​ Create a SOC project portfolio (PDF/LinkedIn/GitHub).​

3.​ Revise SOC interview questions & practice incident reporting.​

Final Project:​
“My Home SOC Lab” – Document your full setup, attacks detected, and reports generated.

✅ End of 3 Months – You Will Have:


●​ Practical experience with SIEM, IDS, Firewalls, Vulnerability Scanners, Malware &
Phishing Analysis​

●​ SOC Investigation Portfolio to show employers​

●​ Knowledge of compliance frameworks & IR playbooks​

●​ Confidence to work as a Tier 1 SOC Analyst​

Common questions

Powered by AI

Wazuh contributes to threat hunting strategies by providing a comprehensive platform for security monitoring, threat detection, and compliance management. It collects security data across diverse endpoints, enabling analysts to perform real-time log analysis and correlation, which is critical for identifying Indicators of Compromise (IoCs) and unusual patterns. The integration of Wazuh in SOC environments allows for continuous improvement of threat hunting methodologies and enhances proactive defense mechanisms .

Tools like Wireshark play a critical role in SOC operations by providing detailed insights into network traffic. They allow analysts to capture, visualize, and inspect packet-level data, helping to identify anomalies, unauthorized access attempts, or data exfiltration activities. Through packet analysis, SOC teams can reconstruct security incidents, trace attacker activities, and gather evidence crucial for post-incident forensics .

Stateful firewalls operate at the network layer and track the state of active connections, allowing or blocking traffic based on state, port, and protocol. They are limited in handling advanced threats as they do not inspect the application layer. In contrast, next-generation firewalls (NGFWs) provide deeper inspection capabilities, including application-level traffic analysis, intrusion prevention, and integrated threat intelligence, making them more effective for advanced threat management .

Open-source tools like Security Onion benefit small enterprise SOCs by providing cost-effective comprehensive network security monitoring capabilities. They offer functionalities such as traffic analysis, intrusion detection, and log management without expensive licensing fees, making them accessible to budget-constrained organizations. Additionally, the customization and active community support inherent in open-source solutions allow for tailored implementations that can meet specific security needs and improve overall threat detection and response capabilities .

Sandboxing is significant in malware analysis as it allows SOC analysts to execute and observe malware behavior in a controlled, isolated environment without risking network damage. This process helps identify malware characteristics, such as file manipulation and network communication attempts, facilitating deeper understanding and remediation. Sandboxing supports SOC operations by enabling safe analysis of potential threats and informing defensive strategies .

When prioritizing incidents during threat triage, the primary considerations include the severity and potential impact of the threat, the organization’s critical assets affected, and the threat actor’s capabilities and intentions. Properly prioritizing incidents ensures that the most critical threats are addressed swiftly, optimizing resource allocation and reducing potential damage. This systematic approach enhances incident response efficiency by ensuring timely identification and containment of significant threats .

The MITRE ATT&CK framework is crucial for incident response playbooks as it provides a comprehensive matrix of tactics and techniques used by attackers, allowing SOC teams to understand and anticipate potential threats. It aids in creating detailed playbooks that guide analysts through detection, analysis, and mitigation processes based on known adversary behaviors, thereby enhancing proactive threat hunting and improving incident response efficiency .

Analyzing an email header assists in identifying potential phishing attacks by revealing crucial information about the email's origin, path, and the legitimacy of the sending domain. It includes data such as the sender's IP address, SPF/DKIM/DMARC records, and potential spoofing signs. This analysis can uncover inconsistencies or anomalies indicating phishing attempts, aiding SOC analysts in early detection and response .

Continuous vulnerability management involves regular scanning and assessment of vulnerabilities, risk prioritization, and ongoing remediation efforts. This process allows organizations to keep up with emerging threats and vulnerabilities, ensuring that security measures are up-to-date and reducing the window of exposure. Within a SOC context, this ongoing process helps maintain a strong security posture by actively identifying and addressing potential weaknesses before they can be exploited .

The CIA triad is fundamental to network monitoring and threat detection as it provides a framework for assessing the security posture of information and systems. Confidentiality safeguards against unauthorized access, integrity ensures accuracy and trustworthiness, and availability maintains service usability. A SOC Analyst leveraging these principles can detect potential breaches impacting these areas, guiding effective incident response strategies to uphold organizational security .

You might also like