SOC Analyst: roadmap

#5 in "Web Security" progression
Python
SOC Analyst: roadmap thumbnail

Updated: Aug 21, 2026

In this project

Wanna become a Security Operations Center Analyst (SOC)?

I've prepared a roadmap for you to learn a new profession just in one Guide.

Ready? Let's dive into. 


Lessons

  1. #1.Short version of full roadmap #1
  2. #2.1. Networking #2
  3. #3.HTTP/HTTPS #3
  4. #4.OSI / TCP-IP #4
  5. #5.TCP vs UDP #5
  6. #6.IP addressing / subnetting #6
  7. #7.ARP #7
  8. #8.DNS #8
  9. #9.DHCP #9
  10. #10.TLS basics #10
  11. #11.SSH #11
  12. #12.SMTP #12
  13. #13.FTP/SFTP #13
  14. #14.SMB #14
  15. #15.LDAP #15
  16. #16.Kerberos #16
  17. #17.ICMP #17
  18. #18.NAT #18
  19. #19.VPN #19
  20. #20.proxies #20
  21. #21.firewalls #21
  22. #22.Ports and protocols #22
  23. #23.Routing basics #23
  24. #24.VLANs #24
  25. #25.IPv4/IPv6 basics #25
  26. #26.Packet capture #26
  27. #27.TCP handshake #27
  28. #28.DNS queries #28
  29. #29.HTTP requests #29
  30. #30.Suspicious connections #30
  31. #31.Port scanning #31
  32. #32.C2 traffic #32
  33. #33.Beaconing #33
  34. #34.Lateral movement #34
  35. #35.Wireshark #35
  36. #36.2. Linux #36
  37. #37.Linux filesystem #37
  38. #38.Linux permissions #38
  39. #39.Linux users/groups #39
  40. #40.Linux processes #40
  41. #41.Linux services #41
  42. #42.Linux systemd #42
  43. #43.Linux SSH #43
  44. #44.Linux cron #44
  45. #45.Linux environment variables #45
  46. #46.Linux networking commands #46
  47. #47.Linux package management #47
  48. #48.Linux logs #48
  49. #49.Linux shell/Bash #49
  50. #50.3. Windows #50
  51. #51.Windows architecture #51
  52. #52.Windows users/groups #52
  53. #53.Linux services #53
  54. #54.Linux processes #54
  55. #55.Windows registry #55
  56. #56.Windows scheduled tasks #56
  57. #57.Windows PowerShell #57
  58. #58.Windows networking #58
  59. #59.Active Directory basics #59
  60. #60.Group Policy #60
  61. #61.Authentication #61
  62. #62.Kerberos #62
  63. #63.NTLM #63
  64. #64.Windows Event Logs #64
  65. #65.4. Cybersecurity fundamentals #65
  66. #66.CIA triad #66
  67. #67.Authentication vs authorization #67
  68. #68.Least privilege principle #68
  69. #69.Defense in depth #69
  70. #70.Encryption #70
  71. #71.Hashing #71
  72. #72.Digital signatures #72
  73. #73.Certificates #73
  74. #74.PKI #74
  75. #75.MFA #75
  76. #76.Access control #76
  77. #77.Vulnerabilities #77
  78. #78.Exploits #78
  79. #79.Malware #79
  80. #80.Phishing #80
  81. #81.Ransomware #81
  82. #82.Brute force #82
  83. #83.Credential attacks #83
  84. #84.Privilege escalation #84
  85. #85.Persistence #85
  86. #86.Lateral movement #86
  87. #87.Сommand & control #87
  88. #88.Data exfiltration #88
  89. #89.MITRE ATT&CK #89
  90. #90.Logs — this is where SOC really starts #90
  91. #91.5. SIEM #91
  92. #92.Microsoft Sentinel #92
  93. #93.Splunk #93
  94. #94.Elastic Security #94
  95. #95.Microsoft Sentinel + Splunk/Elastic concepts #95
  96. #96.6. Detection engineering #96
  97. #97.7. Incident Response #97
  98. #98.8. Threat Intelligence #98
  99. #99.9. EDR/XDR #99
  100. #100.10. Malware analysis — but only the SOC level #100
  101. #101.11. Cloud security #101
  102. #102.12. Automation / scripting #102
  103. #103.13. Vulnerability management #103
  104. #104.14. Basic offensive security #104
  105. #105.15. SOC operations #105
  106. #106.16. Threat hunting #106
  107. #107.17. Professional communication #107