visitor@thefish.nz:~$ cat learning-paths/security-operations.txt

READING PATH

Security Operations

A practical route through thefish.nz for SOC and Security Operations analysts. Start with investigation methodology, build through common incident types and threat hunting, then add the CIS and NIST framework knowledge commonly requested in Security Operations roles.

For: SOC Analyst, Security Operations Analyst, Senior SOC Analyst

17 articles 13 essential 1 recommended 2 optional 1 reference ~411 min total

Start Here

Build the investigation mindset first.

  1. essential Alert to Conclusion: Investigating Without Tunnel Vision

    A practical SOC methodology for moving from a raw alert to a defensible conclusion, covering hypothesis testing, timelines, scope and the difference between detection and diagnosis.

    ~17 min

  2. essential One Alert Is Not the Incident: Scoping Security Incidents in the SOC

    A working method for determining how far a confirmed compromise actually reaches: pivoting from IOCs to behaviour, scoping hosts, identities, email and infrastructure, and reporting scope honestly as it changes.

    ~27 min

Core Investigation Skills

The everyday territory: identity, phishing, telemetry, PowerShell, ransomware.

  1. essential Windows Event Logs for SOC Analysts: What an Event ID Actually Proves

    A practical guide to reasoning about Windows Event Logs during an investigation: which logs and Event IDs are genuinely useful, what they do and don't prove, and how they combine into a defensible timeline.

    ~27 min

  2. essential Identity Attacks for SOC Analysts: Sessions, Tokens, MFA and Account Compromise

    A successful login proves the identity provider accepted the authentication material, not that the legitimate user is behind it. A practical guide to investigating sessions, tokens, MFA, OAuth consent and mailbox compromise.

    ~24 min

  3. essential From Header to Host: Investigating Phishing in the SOC

    A phishing investigation isn't finished when you decide whether the email looks malicious. A practical guide to following the evidence from headers and URLs through delivery, interaction, endpoint and identity impact.

    ~27 min

  4. recommended SPF, DKIM and DMARC: What They Actually Prove (and What They Don't)

    A practical guide to reading SPF, DKIM and DMARC results in email headers: what each mechanism actually authenticates, how alignment works, and where phishing investigations go wrong.

    ~18 min

  5. essential The IP Isn't the Attacker: A SOC Analyst's Guide to NAT, VPNs and Proxies

    A practical SOC analyst's guide to what a source IP address actually represents during an investigation: NAT, CGNAT, VPNs, proxies, Tor, CDNs and how to tell observation from attribution.

    ~20 min

  6. essential PowerShell Is Not the Alert: Investigating Living-off-the-Land Activity

    A practical guide to investigating PowerShell and native Windows living-off-the-land tools in a SOC: what to check, what a signature actually proves, and why the tool is never the verdict.

    ~23 min

  7. essential Ransomware Before the Ransomware: What the SOC Should See Before Encryption Starts

    Ransomware encryption is usually a late-stage event, not the start of an intrusion. A practical look at initial access brokers, valid credentials, living-off-the-land activity and the warning signs a SOC sees before deployment.

    ~37 min

Move Beyond Reactive Investigation

From closing alerts to actively looking for what hasn't fired an alert yet.

  1. essential Threat Hunting for SOC Analysts: Turning a Suspicion Into a Searchable Hypothesis

    Threat hunting is not searching logs until something looks strange. A practical guide to building testable hunt hypotheses, evolving searches from indicator to behaviour to correlation, with worked SPL and KQL examples.

    ~25 min

Framework Literacy

The framework knowledge most useful when a Security Operations role asks for CIS or NIST experience.

  1. essential Beyond the Alert: CIS Critical Security Controls v8.1 for SOC Analysts

    A practical, non-checklist guide to the CIS Critical Security Controls v8.1 for SOC analysts: what the 18 Controls and their Safeguards actually mean, how Implementation Groups work, and how to use the framework to explain why an incident was possible, not just what happened.

    ~27 min

  2. essential Six Functions, Not Six Steps: NIST CSF 2.0 for SOC Analysts

    A practical guide to NIST Cybersecurity Framework 2.0 for SOC analysts: what Govern, Identify, Protect, Detect, Respond and Recover actually mean, why they aren't incident-response stages, and how to use them to see where an alert really fits.

    ~27 min

Interview Preparation

Put the investigation mindset and framework literacy into words.

  1. essential How to Think Like a SOC Analyst in an Interview

    A practical guide to articulating SOC investigation methodology in an interview: how to move from incomplete evidence to a defensible decision, and explain why, instead of just naming tools.

    ~27 min

  2. essential CIS, NIST, ISO 27001 and NZISM: The Interview Guide for Security Practitioners

    A concise revision guide for talking confidently about CIS Controls, NIST CSF 2.0, ISO 27001 and NZISM in a security interview: 60-second answers, honest ways to answer without formal GRC experience, and 20 questions with model answers.

    ~16 min

Further Depth

Optional reading for analysts moving toward assurance and cross-framework work.

  1. optional A Claim Is Not Evidence: Security Assurance for SOC Analysts

    How to take the evidence-based reasoning SOC analysts already use during investigations and apply it to control assurance, supplier assurance and risk findings: claim, evidence, validation, finding, risk, treatment, residual risk.

    ~29 min

  2. optional Present Is Not Effective: How to Test Security Controls

    A practical guide to security control testing: the difference between design, implementation and operating effectiveness, how to define a population, sample it properly, and test ten common controls with real evidence, from MFA to backups.

    ~17 min

  3. reference Same Problem, Four Lenses: CIS vs NIST vs ISO 27001 vs NZISM

    A practical comparison of CIS Controls, NIST CSF 2.0, ISO 27001 and NZISM: what each is really for, where they overlap, and a concrete recommendation for which to learn first depending on your role.

    ~23 min

← all reading paths