Security Analyst Skill Development
Books to Read
- Blue Team Field Manual (BTFM)
- The Blue Team Handbook: SOC
- Practical Packet Analysis
Skills to Develop
- Log Analysis
- Windows logs
- Event Viewer
- Common events
- Suspicious events
- Sysmon
- Web server logs
- Linux Logs
- Audit logs (
/var/logs/audit.log) - Auth logs (
/var/logs/auth.log)ausearch -i -if
- Web server logs (
/var/logs/apache2/access.log) - Sysmon
- Audit logs (
- Firewall logs
- DNS logs
- Proxy logs
- Know how to read each
- Understand common attacks on each how the look in logs
- Know common EventIDs
- Windows logs
- Process Analysis
- Windows Processes
- Common / normal processes
- Process trees
- Tools:
- Sysinternals
- Process Monitor (ProcMon)
- Process Hacker 2
- Linux Processes
- Common / normal processes
- Suspicious processes
- Windows Processes
- Malware Analysis
- Builds off process analysis skills, scripting / CLI commands, and general suspicious activity
- Tools:
- VirusTotal
- HybridAnalysis
- ANY.RUN
- PeStudio (Windows)
- Traffic Analysis
- WireShark
- tcpdump
- Zeek
- Know how all the foundational protocols work and look like
- Understand common traffic anomalies
- Understand how to investigate problems
- Understand how common network attacks work and look like
- ARP Spoofing
- DNS Spoofing
- MITM
- Insecure protocol data exfiltration (HTTP, FTP, ICMP)
- SIEM
- Know how SIEM works
- Know how to write queries
- Know how to analyze ingested logs
- Know how to correlate events
- Know how to read and build dashboards
- Tools:
- Splunk (most important)
- Microsoft Sentinel (probably important)
- ELK Stack (Kibana) (optional but good)
- IR - Event Triage
- Know IR process
- Know common IoCs
- Know common TTPs
- Understand how to analyze various events
- EDR Tools
- Crowdstrike Falcon
- Microsoft Defender for Endpoint
- SentinelOne
- Phishing Analysis
- Analyze email headers
- analyze attached files (malware analysis)
Frameworks
- MITRE ATTACK
- NIST IR
- Cyber kill chain
- Unified kill chain
- Diamond Model of Intrusion Analysis
Hands-On Training
Learn Phase
- RangerForce/Cyberbit Free Edition
- 80% done
- Blue Team Junior Analyst (Security Blue Team)
- SOC Level 1 (TryHackMe)
- MITRE ATT&CK (AttackIQ)
- length: 18 hrs
- Splunk Core Certified User ($130)
- AZ-900 (~~
50 with discount) - SOC Analyst Job Role Path (HackTheBox Academy)
- SC-900 (~~
50 discount) - AWS CCP ($100)
- may be vouchers for doing training or practice exams
- SC-200 ($165)
- Certified CyberDefender Level 1 (CCDL1) (~~
250 w/ discount) - Security Operations (SOC) 101 (TCM Security) ($30/mo)
Application Phase
- Security Analyst I, II, III, IV Paths (kc7cyber) (100% Free)
- Only focuses on KQL (Microsoft Sentinal) investigations
- SOC Analyst Tier 1 (CyberDefenders) ($20)
- traffic analysis, log analysis, splunk, sentinal
- Splunk Boss of the SOC (SOC) Labs
- Splunk
- Phishing Analysis practice
- Malware-Traffic-Analysis.net
- Microsoft Azure Skills
Projects
- Home network lab
- SOC Detection Lab (local pc)
- malware lab
- soc lab
- Azure Lab (Cloud)
Extras
- Blue Team Labs Online (BTLO)
- Security Engineer (TryHackMe)
- SOC Level 2 (TryHackMe)
- Defending Azure (TryHackMe)
- AI Security (TryHackMe)
-
SOC Analyst Learning Path (LetsDefend.io)- Terrible: barely english, poor platform design