2-Week SOC Analyst Study Plan
Day 1 – SOC & SIEM Fundamentals
• Study: What is SOC? SOC Tiers (1, 2, 3). SIEM basics (Splunk, ELK, QRadar).
• Practice: Explore free SIEM labs (Splunk/ELK).
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 2 – Networking & Protocols
• Study: OSI & TCP/IP models, Ports & Protocols.
• Practice: Capture packets in Wireshark (HTTP, DNS).
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 3 – IDS/IPS & Firewalls
• Study: IDS vs IPS (Snort, Suricata, Zeek).
• Practice: Create a simple Snort rule.
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 4 – Endpoint Security
• Study: Antivirus vs EDR, Endpoint monitoring tools.
• Practice: Investigate Windows Event Viewer for failed logon.
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 5 – Linux System Administration
• Study: Linux commands, file system, system logs.
• Practice: Detect failed SSH logins in /var/log/[Link].
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 6 – Microsoft System Administration
• Study: Active Directory basics, Event Viewer logs.
• Practice: Simulate failed login and detect in logs.
• Resources:
• - [Link]
rectory-domain-services-overview
• - [Link]
• - [Link]
Day 7 – Review & Mini Test
• Review: SOC, SIEM, IDS/IPS, Endpoint basics.
• Practice: SOC fundamentals lab.
• Resources:
• - [Link]
• - [Link]
Day 8 – Incident Response & Playbooks
• Study: Incident lifecycle (Detection → Analysis → Containment → Eradication → Recovery →
Lessons Learned).
• Practice: Write a simple phishing incident report.
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 9 – Log Analysis (SIEM Practice)
• Study: Log sources (Firewall, IDS, Proxy).
• Practice: Identify false positives in SIEM alerts.
• Resources:
• - [Link]
• - [Link]
Day 10 – Threat Intelligence
• Study: MITRE ATT&CK;, IOC vs IOA.
• Practice: Analyze IPs & hashes in VirusTotal.
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 11 – Cybersecurity Policies
• Study: ISO 27001, NIST CSF, CIA triad.
• Practice: Read a sample policy & map to SOC tasks.
• Resources:
• - [Link]
• - [Link]
• - [Link]
Day 12 – Threat Detection
• Study: Indicators of Compromise (IOC), Indicators of Attack (IOA).
• Practice: Extract IOCs from logs.
• Resources:
• - [Link]
• - [Link]
Day 13 – English & Technical Reporting
• Study: SOC vocabulary (incident, alert, escalate, detection, remediation).
• Practice: Write a short incident report in English.
• Resources:
• - [Link]
• - [Link]
Day 14 – Final Review & Mock Interview
• Review: Key SOC concepts, practice interview questions.
• Practice: Prepare a full incident report (from detection to remediation).
• Resources:
• - [Link]
• - [Link]