Security Operations — Cybersecurity Analyst / Ethical Hacker Roadmap
Detecting, triaging and responding to real attacks as part of a security operations team
Steps in Security Operations
- What Is a SOC — intermediate · The structure, shifts and responsibilities of a Security Operations Center
- SIEM Fundamentals — intermediate · How a SIEM aggregates and correlates logs from across an entire organization
- Working with Splunk and the Elastic Stack — intermediate · Querying and building detections in the two most widely used SIEM platforms
- Log Analysis — intermediate · Reading authentication, firewall and application logs to spot signs of compromise
- Alert Triage — intermediate · Deciding which of hundreds of daily alerts is a real threat worth escalating
- Incident Response Process — intermediate · The identify, contain, eradicate, recover and lessons-learned cycle for a real incident
- Threat Hunting Basics — advanced · Proactively searching for attackers who evaded automated detection
Part of
- Cybersecurity Analyst / Ethical Hacker roadmap — the full learning path