A practical SOC methodology for moving from a raw alert to a defensible conclusion, covering hypothesis testing, timelines, scope and the difference between detection and diagnosis.
~17 min
visitor@thefish.nz:~$ cat learning-paths/security-operations.txt
READING PATH
A practical route through thefish.nz for SOC and Security Operations analysts. Start with investigation methodology, build through common incident types and threat hunting, then add the CIS and NIST framework knowledge commonly requested in Security Operations roles.
For: SOC Analyst, Security Operations Analyst, Senior SOC Analyst
17 articles 13 essential 1 recommended 2 optional 1 reference ~411 min total
Build the investigation mindset first.
A practical SOC methodology for moving from a raw alert to a defensible conclusion, covering hypothesis testing, timelines, scope and the difference between detection and diagnosis.
~17 min
A working method for determining how far a confirmed compromise actually reaches: pivoting from IOCs to behaviour, scoping hosts, identities, email and infrastructure, and reporting scope honestly as it changes.
~27 min
The everyday territory: identity, phishing, telemetry, PowerShell, ransomware.
A practical guide to reasoning about Windows Event Logs during an investigation: which logs and Event IDs are genuinely useful, what they do and don't prove, and how they combine into a defensible timeline.
~27 min
A successful login proves the identity provider accepted the authentication material, not that the legitimate user is behind it. A practical guide to investigating sessions, tokens, MFA, OAuth consent and mailbox compromise.
~24 min
A phishing investigation isn't finished when you decide whether the email looks malicious. A practical guide to following the evidence from headers and URLs through delivery, interaction, endpoint and identity impact.
~27 min
A practical guide to reading SPF, DKIM and DMARC results in email headers: what each mechanism actually authenticates, how alignment works, and where phishing investigations go wrong.
~18 min
A practical SOC analyst's guide to what a source IP address actually represents during an investigation: NAT, CGNAT, VPNs, proxies, Tor, CDNs and how to tell observation from attribution.
~20 min
A practical guide to investigating PowerShell and native Windows living-off-the-land tools in a SOC: what to check, what a signature actually proves, and why the tool is never the verdict.
~23 min
Ransomware encryption is usually a late-stage event, not the start of an intrusion. A practical look at initial access brokers, valid credentials, living-off-the-land activity and the warning signs a SOC sees before deployment.
~37 min
From closing alerts to actively looking for what hasn't fired an alert yet.
Threat hunting is not searching logs until something looks strange. A practical guide to building testable hunt hypotheses, evolving searches from indicator to behaviour to correlation, with worked SPL and KQL examples.
~25 min
The framework knowledge most useful when a Security Operations role asks for CIS or NIST experience.
A practical, non-checklist guide to the CIS Critical Security Controls v8.1 for SOC analysts: what the 18 Controls and their Safeguards actually mean, how Implementation Groups work, and how to use the framework to explain why an incident was possible, not just what happened.
~27 min
A practical guide to NIST Cybersecurity Framework 2.0 for SOC analysts: what Govern, Identify, Protect, Detect, Respond and Recover actually mean, why they aren't incident-response stages, and how to use them to see where an alert really fits.
~27 min
Put the investigation mindset and framework literacy into words.
A practical guide to articulating SOC investigation methodology in an interview: how to move from incomplete evidence to a defensible decision, and explain why, instead of just naming tools.
~27 min
A concise revision guide for talking confidently about CIS Controls, NIST CSF 2.0, ISO 27001 and NZISM in a security interview: 60-second answers, honest ways to answer without formal GRC experience, and 20 questions with model answers.
~16 min
Optional reading for analysts moving toward assurance and cross-framework work.
How to take the evidence-based reasoning SOC analysts already use during investigations and apply it to control assurance, supplier assurance and risk findings: claim, evidence, validation, finding, risk, treatment, residual risk.
~29 min
A practical guide to security control testing: the difference between design, implementation and operating effectiveness, how to define a population, sample it properly, and test ten common controls with real evidence, from MFA to backups.
~17 min
A practical comparison of CIS Controls, NIST CSF 2.0, ISO 27001 and NZISM: what each is really for, where they overlap, and a concrete recommendation for which to learn first depending on your role.
~23 min