Security Analyst Skill Development


Books to Read

  • Blue Team Field Manual (BTFM)
  • The Blue Team Handbook: SOC
  • Practical Packet Analysis

Skills to Develop

  • Log Analysis
    • Windows logs
      • Event Viewer
      • Common events
      • Suspicious events
      • Sysmon
      • Web server logs
    • Linux Logs
      • Audit logs (/var/logs/audit.log)
      • Auth logs (/var/logs/auth.log)
        • ausearch -i -if
      • Web server logs (/var/logs/apache2/access.log)
      • Sysmon
    • Firewall logs
    • DNS logs
    • Proxy logs
    • Know how to read each
    • Understand common attacks on each how the look in logs
    • Know common EventIDs
  • Process Analysis
    • Windows Processes
      • Common / normal processes
      • Process trees
      • Tools:
        • Sysinternals
        • Process Monitor (ProcMon)
        • Process Hacker 2
    • Linux Processes
      • Common / normal processes
      • Suspicious processes
  • Malware Analysis
    • Builds off process analysis skills, scripting / CLI commands, and general suspicious activity
    • Tools:
      • VirusTotal
      • HybridAnalysis
      • ANY.RUN
      • PeStudio (Windows)
  • Traffic Analysis
    • WireShark
    • tcpdump
    • Zeek
    • Know how all the foundational protocols work and look like
    • Understand common traffic anomalies
    • Understand how to investigate problems
    • Understand how common network attacks work and look like
      • ARP Spoofing
      • DNS Spoofing
      • MITM
      • Insecure protocol data exfiltration (HTTP, FTP, ICMP)
  • SIEM
    • Know how SIEM works
    • Know how to write queries
    • Know how to analyze ingested logs
    • Know how to correlate events
    • Know how to read and build dashboards
    • Tools:
      • Splunk (most important)
      • Microsoft Sentinel (probably important)
      • ELK Stack (Kibana) (optional but good)
  • IR - Event Triage
    • Know IR process
    • Know common IoCs
    • Know common TTPs
    • Understand how to analyze various events
  • EDR Tools
    • Crowdstrike Falcon
    • Microsoft Defender for Endpoint
    • SentinelOne
  • Phishing Analysis
    • Analyze email headers
    • analyze attached files (malware analysis)

Frameworks

  • MITRE ATTACK
  • NIST IR
  • Cyber kill chain
  • Unified kill chain
  • Diamond Model of Intrusion Analysis

Hands-On Training

Learn Phase

Application Phase

Projects

  • Home network lab
  • SOC Detection Lab (local pc)
    • malware lab
    • soc lab
  • Azure Lab (Cloud)

Extras