SOC Analyst Tips & Resources

SOC Analyst Tips & Resources

My SOC journey so far…. 2020-2022.

I have two years of experience in a SOC role and am a Tier 2 SOC analyst.

Over the past two years, I've learned new skills or certifications, and I'll say this much, I have a long way to go. The journey is long, and there's always room to grow and improve.

I just wanted to provide others with some certifications, resources, and books that I found helpful over my two-year period.

Take the following information with a grain of salt. There are security juggernauts out there, and I am not elite in any sense. I love information security and what I do daily. I try to sharpen my skillset via books, certifications, or training platforms. My short-term goal is to move to an incident response analyst role. The long-term goal I want is to be a security manager.

Do understand that Information Security is a life journey and career. No book or training out there will prepare you for a role. That's why you see many security professionals constantly studying for their next certification or sharpening what they already know.

As far as certifications go:

  1. CompTIA Sec+ & Net+: These are not technical certifications, but the theory is vital to understanding the purpose of security and how endpoints communicate. Even if you don't attempt the certifications, I suggest studying the material.
  2. Security Blue Team Level 1: I wish this would have been available when I started, and I don't remember hearing about it back then. BTL1 is hands down a must for any new aspiring SOC analyst. The exam is practical and covers most of the work I do daily. The knowledge and skills you pick up here will make you a more confident SOC analyst. The only downside I dislike is that it's not a well-known certification, but I foresee this changing in the future.
  3. Linux LPI: Linux LPI is an excellent certification for anyone new to Linux. You'll learn about the Linux file structure, distro's, CLI, and basic CLI commands. * I enjoy and recommend Jason Dion's Linux Essentials course.
  4. eJPT: The eJPT training is excellent because you can practice a few red team skills. The training will help you understand the steps threat actors take to compromise a network, and once you complete the training, you can attempt the eJPT certification. The last time I took it, the training material was free. I am not sure anymore.?
  5. Splunk Core User: The last time I took the training, it was free, I am not sure anymore, but it's a great SIEM to pick up as a beginner. You'll probably be asked what SIEM you know during an interview, and Splunk is popular.?
  6. Take Notes: Seriously, you will start noticing that you can't keep track of everything you are learning and start forgetting information. I like OneNote because it sync's across your devices, and you can search for keywords. There are other great applications, so don't just think OneNote is the only option.?

No alt text provided for this image

I will add on to understand how ticketing systems work and follow blogs or articles to know the current threat landscape in IT. Connect with other professionals in your desired role and cross-check job postings; even if you don't qualify for a position, look to see what skills or certifications an employer is looking for and chase after them.

During breakfast, I listen to SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) on Apple Podcasts to see what I missed. I also follow BleepingComputer.com - Technology news and support and other professionals on LinkedIn.

Some resources I found that are great to have bookmarked:?

Books:

In conclusion: What I mentioned above are some certifications, resources, and books that I believe will help aspiring SOC analysts. It's not perfect, but it's a quick view of the information I have picked up so far in my journey.

This is enough to help you create a baseline, but every role out there has different tools that I didn't touch up here. Those you will learn with time, so don't stress too much about it. I would also say pick up a cloud path, but that's another topic in itself.

Feel free to send me a connections request or message if you have some questions. I will try my best to get back to you, but if I take a bit long, please understand that I have other things going on.

Cheers.

Tirth Patel

Co-Founder @ Xaneur | AI Automation & Innovation

2 年

cyber security beginner study material Best book for Cyber security Try #cybersecurity #cybercrime #informationsecurity link Amazon= https://amzn.eu/d/dewGCAU

回复
Mohammad Yusep

Aspiring Cybersecurity Professional / NCSU Cybersecurity Bootcamp 2022.

2 年

Really important thing to know. Thanks !

回复
Emdadur Rahman

Business Growing ↑ Software Architecture | CEO | Cyber Security Consulting |

2 年

Very Helpful for Beginner... Great Article!

回复
Joshua Alabre

SOC Analyst I /Threat Hunter/Threat Intelligence

2 年

Great Post.

回复

要查看或添加评论,请登录

??Carlos E.的更多文章

  • TryHackMe: Security Analyst Level 1 (SAL1) Review

    TryHackMe: Security Analyst Level 1 (SAL1) Review

    Before I begin, I want to thank TryHackMe for giving me the opportunity to take the exam for free—something you don’t…

    5 条评论
  • Insights and resources for aspiring security analysts.

    Insights and resources for aspiring security analysts.

    In July, I will have accumulated four years of experience in a Security Operations Center role. Every now and then, I…

    11 条评论
  • Certified CyberDefender (CCD) Review

    Certified CyberDefender (CCD) Review

    In the ever-changing landscape of cybersecurity, continuous learning is not just a necessity but a vital imperative. A…

    7 条评论
  • General tips for junior SOC Analysts.

    General tips for junior SOC Analysts.

    Let me start by saying that I'm not the best SOC analyst out there, and I have room for improvement. That being said, I…

    12 条评论
  • The learning curve with certifications.

    The learning curve with certifications.

    Hi everyone, I wanted to share my personal experience with certifications. I have a few certifications from various…

    3 条评论

社区洞察

其他会员也浏览了