Skip to content

Latest commit

 

History

History
143 lines (128 loc) · 11.2 KB

File metadata and controls

143 lines (128 loc) · 11.2 KB

Awesome SOC / Blue Team Learning Resources

Security Operations Center (SOC) and blue-team work covers monitoring, triage, detection engineering, log analysis, threat hunting, alert tuning, and incident handoff. It sits at the intersection of SIEM/XDR tooling, detection content (Sigma, KQL, SPL, Elastic DSL), and analyst methodology (pyramid of pain, Kill Chain, ATT&CK).

ToC

  1. Books
  2. Videos
  3. Free/Paid Courses
  4. Free/Paid Labs
  5. SOC / Blue Team Tools
  6. Certifications
  7. Blogs/Articles

Books

  1. The Practice of Network Security Monitoring by Richard Bejtlich (No Starch) - Foundational NSM book; still essential.
  2. Blue Team Handbook: Incident Response Edition by Don Murdoch
  3. Blue Team Handbook: SOC, SIEM, and Threat Hunting Use Cases by Don Murdoch
  4. Crafting the InfoSec Playbook by Jeff Bollinger et al. (O'Reilly)
  5. Applied Network Security Monitoring by Chris Sanders, Jason Smith
  6. Intelligence-Driven Incident Response by Scott J. Roberts, Rebekah Brown (O'Reilly, 2nd ed 2023)
  7. The Tao of Network Security Monitoring by Richard Bejtlich - Older but classic.
  8. Practical Threat Intelligence and Data-Driven Threat Hunting by Valentina Costa-Gazcon (Packt)
  9. The Threat Hunter's Handbook by Anton Chuvakin et al. (free, Chronicle / Google)

Videos

  1. 13Cubed - DFIR & Windows internals - High-quality, long-running channel.
  2. The Taggart Institute - SOC/blue-team fundamentals.
  3. SANS Blue Team Summit archives
  4. BSides / DEF CON Blue Team Village
  5. Microsoft Security community channel
  6. Black Hills Information Security webcasts (free)
  7. John Hubbard - SOC / blue-team content
  8. MITRE ATT&CKcon archives

Free/Paid Courses

Free / low-cost

  1. Blue Team Labs Online - BTL1 free content
  2. LetsDefend - free tier
  3. TryHackMe - SOC Level 1 & 2 paths
  4. HackTheBox Academy - SOC Analyst path
  5. Splunk Fundamentals 1 (free)
  6. Microsoft Learn - SC-200 Security Operations Analyst (free)
  7. Elastic Security - free training on elastic.co
  8. AttackIQ Academy - Detection Engineering (free)
  9. Active Countermeasures - free courses by Chris Brenton

Paid

  1. SANS SEC450: Blue Team Fundamentals by John Hubbard - the canonical SOC course.
  2. SANS SEC555: SIEM with Tactical Analytics
  3. SANS SEC511: Continuous Monitoring and Security Operations
  4. BTL1 / BTL2 by Security Blue Team - Very practical certs.
  5. Zero Point Security - Sentinel / DFIR Fundamentals
  6. CyberDefenders Bootcamp

Free/Paid Labs

  1. CyberDefenders - Blue Team CTFs - Dozens of free DFIR / SOC challenges.
  2. LetsDefend - guided SOC incidents
  3. TryHackMe SOC paths / Red-vs-Blue rooms
  4. Blue Team Labs Online
  5. RangeForce - Enterprise-grade blue-team labs.
  6. DetectionLab by Chris Long - Full AD + ELK + Velociraptor lab stack (note: archived 2023; see forks).
  7. SOC Simulator by SecurityBlueTeam
  8. HELK - Hunting ELK by Cyb3rWard0g
  9. Security Datasets project (Mordor) - Pre-recorded attack logs for practice.
  10. Splunk BOTS (Boss of the SOC) v1-v3 datasets
  11. APT Simulator - Quick IoC generation for detection testing.

SOC / Blue Team Tools

SIEM / log platforms

  1. Splunk Enterprise Security / Splunk Free
  2. Microsoft Sentinel - Cloud-native SIEM with KQL.
  3. Elastic Security (ELK / Elastic Stack)
  4. Wazuh - Open-source SIEM/XDR.
  5. Graylog
  6. Google SecOps (Chronicle)
  7. IBM QRadar
  8. Sumo Logic
  9. CrowdStrike Falcon Next-Gen SIEM

EDR / XDR

  1. CrowdStrike Falcon
  2. Microsoft Defender for Endpoint
  3. SentinelOne
  4. Sysmon (open-source endpoint telemetry) - Use with SwiftOnSecurity's Sysmon config or Olaf Hartong's config.
  5. OSSEC / Wazuh agent
  6. osquery - SQL-based endpoint telemetry.

Detection content / rules

  1. Sigma - Vendor-neutral detection rule format.
  2. Elastic detection rules
  3. Splunk Security Content
  4. Azure Sentinel Community rules
  5. Atomic Red Team - Adversary test library; essential for detection validation.
  6. Red Canary Mac Monitor / Canary Tokens

Network defense

  1. Zeek, Suricata, Snort 3
  2. Security Onion - Turnkey SOC distro.
  3. Arkime (formerly Moloch) - Full PCAP indexing.
  4. RITA by Active Countermeasures - Beacon / C2 analysis.

SOAR / automation

  1. Shuffle - Open-source SOAR.
  2. TheHive + Cortex - Case management + response.
  3. Tines / Torq - Commercial SOAR.
  4. Splunk SOAR (formerly Phantom)

Threat hunting

  1. Jupyter notebooks + MSTICPy by Microsoft
  2. Hunting ELK (HELK)
  3. Velociraptor - Endpoint hunting & DFIR.
  4. KAPE by Eric Zimmerman

Certifications

  1. BTL1 / BTL2 by Security Blue Team - Very respected practical certs.
  2. GCIA - GIAC Certified Intrusion Analyst (SANS)
  3. GCIH - GIAC Certified Incident Handler
  4. GMON - GIAC Continuous Monitoring Certification
  5. GCDA - GIAC Certified Detection Analyst
  6. CompTIA CySA+
  7. Microsoft SC-200 Security Operations Analyst
  8. Cisco CyberOps Associate / Professional
  9. Splunk Core / Splunk Enterprise Security certifications
  10. EC-Council CSA / CTIA
  11. HTB CDSA - Certified Defensive Security Analyst
  12. TCM Security PSAA - Practical SOC Analyst Associate

Blogs/Articles

  1. MITRE ATT&CK - Technique reference every analyst should bookmark.
  2. MITRE D3FEND - Defensive techniques companion.
  3. The DFIR Report - Intrusion walk-throughs with IOCs and Sigma rules.
  4. Red Canary Threat Detection Report (annual)
  5. Microsoft Defender XDR / Sentinel blog
  6. SANS Internet Storm Center diary
  7. Pyramid of Pain - David Bianco
  8. Palantir Alerting and Detection Strategy framework
  9. Detection Engineering Cookbook
  10. Awesome SOC GitHub list
  11. Detection Engineering Weekly newsletter by Zack "techstackr" Allen
  12. Chris Sanders' blog (NSM, investigation theory)
  13. Anton Chuvakin's blog - SOC/SIEM research
  14. Florian Roth (Nextron) - detection research and YARA/Sigma rules
  15. OSSEM - Open Source Security Events Metadata