LEVEL 1
Networking
Linux
Windows
Command line
↓
LEVEL 2
Cybersecurity fundamentals
Authentication
Encryption
Common attacks
MITRE ATT&CK
↓
LEVEL 3
Logs & telemetry
Windows Event Logs
Sysmon
Linux logs
DNS
Firewall
↓
LEVEL 4
SIEM
Splunk / Sentinel / Elastic
Queries
Alerts
Correlation
↓
LEVEL 5
SOC Investigation
Alert triage
IOC investigation
Incident timelines
False positives
↓
LEVEL 6
Detection & Response
Sigma
Detection engineering
EDR/XDR
Incident response
↓
LEVEL 7
Advanced SOC
Threat hunting
Threat intelligence
Cloud security
Malware analysis
↓
LEVEL 8
Automation
Python
PowerShell
APIs
SOAR
Automation projects