Get back to the cyber security with new blue team roadmap

Eazy_web
2 min readMar 21, 2024

--

hi , i am Mohamed Musfik in past year i am focused in the red team i have much interest to hack into system and network sometimes with some phishing attack with fun in (Instagram whats app ,Facebook) that's really have much fun in my career

that time i faced one the most beautiful memory with mine and the sad reality of the story i get outed in the cyber security and spend time in that moment by that a came to end with sad reality moment and memory

now i am get back to the cyber security with the new plan and the idea with the new path on the cyber security yes, i am choose to with the blue team but i don't Lev the red team activity

My plan to get into the blue team get update in this page of the eazy wab blog page !!!!

first i choose to enter with the CC (Certificate in Cyber security) isc2 certificate and now its going with the free certificate you can apply with the below link!!!!

https://www.isc2.org/landing/1mcc

Now path of the learning start with the TryHackMe and HackTheBox

first i am going with the Tryhackme path of the leaning

Pre security

  • Cyber security basics
  • Networking basics and weaknesses
  • The web and common attacks
  • Learn to use the Linux operating system

SOC Level 1

The responsibilities of a Junior Security Analyst or Tier 1 SOC Analyst include the following:

  • Monitor and investigate alerts (most of the time, it’s a 24x7 SOC operations environment)
  • Configure and manage security tools
  • Develop and implement IDS signatures
  • Escalate the security incidents to the Tier 2 and Team Lead if needed

Security Engineer

  • Network security engineering
  • System security engineering
  • Software security engineering
  • Risk management & responding to incidents

SOC Level 2

  • Security operations
  • Introductory incident response
  • Malware analysis
  • Threat hunting and threat emulation

Cyber Defense

  • Detect threats
  • Gather threat actor intelligence
  • Understand and emulate adversary TTPs
  • Identify and respond to incidents

after that i go through the Hackthebox learning path

CDSA certification (Certified Defensive Security Analyst)

it contains the topic of the

SOC Processes & Methodologies

  • Incident Handling Process
  • Security Incident Reporting

SIEM Operations (ELK/Splunk) & Tactical Analytics

  • Security Monitoring & SIEM Fundamentals
  • Understanding Log Sources & Investigating with Splunk
  • Detecting Windows Attacks with Splunk

Log Analysis

  • Windows Event Logs & Finding Evil

Threat Hunting

  • Introduction to Threat Hunting & Hunting With Elastic

Active Directory Attack Analysis

  • Windows Attacks & Defense

Network Traffic Analysis

  • Intro to Network Traffic Analysis
  • Intermediate Network Traffic Analysis
  • Working with IDS/IPS

Malware Analysis

  • Introduction to Malware Analysis
  • JavaScript De obfuscation

DFIR Operations

  • YARA & Sigma for SOC Analysts
  • Introduction to Digital Forensics

i hope the continue learning make more knowledgeable in the cyber security career now i update the course details path and walk through in the medium and cover the cyber security framework and other related the security

i try to complete those all the certificate and other in 3 months inshallah help me to get that knowledge and grow with me

inshallah !!!!

--

--

Eazy_web
Eazy_web

Written by Eazy_web

Welcome to Eazy web! I delve into Blue Team and Red Team strategies offering teaching and growth tips. Join me to explore travel, financial management, and more

No responses yet