Section 1
Blue Team and SOC Fundamentals
Understand SOC roles, operating models, and core response functions.
Milestone-based roadmap for SOC operations, detection engineering, incident response, forensics, and modern cloud telemetry.
This plan focuses on monitoring, detection, and response across endpoint, network, application, and cloud environments. It helps build practical skills for Blue Team, SOC, Detection Engineering, and Incident Response roles.
Expected pace
14-19 weeks
Build through repeated detection tuning and IR exercises.
Focus areas
In short
Section 1
Understand SOC roles, operating models, and core response functions.
Section 2
Learn what to log, how to normalize data, and how SIEM pipelines produce alertable signals.
Section 3
Build reliable detections, map them to ATT&CK, and hunt proactively with hypotheses.
Section 4
Learn to handle incidents end-to-end with clear process, ownership, and stakeholder communication.
Section 5
Understand evidence handling and basic host/cloud artifact analysis for investigations.
Section 6
Extend Blue Team operations into cloud, containerized, and SaaS/IdP-centric environments.
Section 7
Use practical books on SOC operations, IR, DFIR, and intrusion case studies.
Section 8
Watch detection engineering and DFIR case-study talks for practical tactics.
Section 9
Prioritize courses with hands-on labs for SOC, IR/DFIR, and threat hunting workflows.
Section 10
Choose cert path by role goal: SOC analyst, detection engineer, or IR/DFIR specialist.
Section 11
Practice detection and response answers across application, cloud, and identity scenarios.