A structured learning path starting from SOC analyst fundamentals for learners with basic Linux, Python, and cybersecurity skills, guiding you toward a DFIR (Digital Forensics and Incident Response) expert role.
Beginner
120h
soc-analyst
dfir
cybersecurity
incident-response
Card legend
Topic
Milestone
Task
Note
Decision
Project
Grouped
- AI Assist
- Progress
Sign in to use AI Assist
Sign In
Proof of Competence
0%
0 / 30 checkpoints declared
0/15 evidence needed for 100% β max 50% without proof
SOC Analyst Foundations
You can explain the daily workflow of a SOC analyst and identify key SOC tools
Milestone
Describe the SOC analyst role and common tasks in writing (summary)
Checkpoint
Set up a basic alert monitoring workflow using open-source tools (e.g., OSSIM or Security Onion)
Project
You can analyze network traffic for suspicious patterns using packet capture tools
Milestone
Capture and analyze network traffic with Wireshark and identify anomalies (capture file annotated)
Checkpoint
Incident Detection and Response Basics
You can classify security alerts, document triage decisions, and escalate appropriately
Milestone
Investigate sample alerts and produce triage reports (report with clear escalation rationale)
Checkpoint
Create an incident triage template and workflow document for a SOC team
Project
You can query a SIEM system, correlate events, and find suspicious activities
Milestone
Write and run basic SIEM queries to detect brute force or lateral movement (query outputs saved)
Checkpoint
Core Digital Forensics Skills
You can perform basic forensic imaging of a disk and analyze file metadata
Milestone
Create a forensic image of a test drive and extract file metadata (evidence preserved with clear documentation)
Checkpoint
Conduct a forensic timeline analysis using metadata from multiple files
Project
You can capture memory images and perform initial analysis to identify suspicious processes
Milestone
Capture a memory dump from a VM and identify hidden or injected processes using Volatility (analysis report)
Checkpoint
Intermediate DFIR Techniques
You can design an incident response playbook for a ransomware attack scenario
Milestone
Develop and document a step-by-step ransomware incident response playbook (playbook draft)
Checkpoint
Simulate a ransomware incident response in a controlled lab environment
Project
You can reconstruct an attack timeline using consolidated logs and correlate events
Milestone
Build a timeline of a multi-stage attack from given logs (timeline report with event correlation)
Checkpoint
SOC to DFIR Transition Skills
You can automate detection workflows and alert enrichment tasks with Python
Milestone
Develop a script to parse logs and send alerts to a chat tool (working script with documentation)
Checkpoint
Build a simple SOAR playbook prototype automating a phishing alert response
Project
You can create and execute a threat hunt to discover undetected attacker activity
Milestone
Complete a threat hunting exercise in a SIEM environment and document findings (written hunt report)
Checkpoint
Professional Development and Tools Mastery
You can proficiently use key SOC and DFIR tools for analysis and investigation
Milestone
Complete a hands-on exercise with at least 3 different tools, documenting workflows (exercise report)
Checkpoint
Set up a personal DFIR lab integrating multiple tools for combined use
Project
You can create a personalized certification roadmap and career plan toward DFIR
Milestone
Draft a one-year professional development plan including certifications and skill goals (plan document)
Checkpoint