Security Operations Center (SOC) and blue-team work covers monitoring, triage, detection engineering, log analysis, threat hunting, alert tuning, and incident handoff. It sits at the intersection of SIEM/XDR tooling, detection content (Sigma, KQL, SPL, Elastic DSL), and analyst methodology (pyramid of pain, Kill Chain, ATT&CK).
- The Practice of Network Security Monitoring by Richard Bejtlich (No Starch) - Foundational NSM book; still essential.
- Blue Team Handbook: Incident Response Edition by Don Murdoch
- Blue Team Handbook: SOC, SIEM, and Threat Hunting Use Cases by Don Murdoch
- Crafting the InfoSec Playbook by Jeff Bollinger et al. (O'Reilly)
- Applied Network Security Monitoring by Chris Sanders, Jason Smith
- Intelligence-Driven Incident Response by Scott J. Roberts, Rebekah Brown (O'Reilly, 2nd ed 2023)
- The Tao of Network Security Monitoring by Richard Bejtlich - Older but classic.
- Practical Threat Intelligence and Data-Driven Threat Hunting by Valentina Costa-Gazcon (Packt)
- The Threat Hunter's Handbook by Anton Chuvakin et al. (free, Chronicle / Google)
- 13Cubed - DFIR & Windows internals - High-quality, long-running channel.
- The Taggart Institute - SOC/blue-team fundamentals.
- SANS Blue Team Summit archives
- BSides / DEF CON Blue Team Village
- Microsoft Security community channel
- Black Hills Information Security webcasts (free)
- John Hubbard - SOC / blue-team content
- MITRE ATT&CKcon archives
- Blue Team Labs Online - BTL1 free content
- LetsDefend - free tier
- TryHackMe - SOC Level 1 & 2 paths
- HackTheBox Academy - SOC Analyst path
- Splunk Fundamentals 1 (free)
- Microsoft Learn - SC-200 Security Operations Analyst (free)
- Elastic Security - free training on elastic.co
- AttackIQ Academy - Detection Engineering (free)
- Active Countermeasures - free courses by Chris Brenton
- SANS SEC450: Blue Team Fundamentals by John Hubbard - the canonical SOC course.
- SANS SEC555: SIEM with Tactical Analytics
- SANS SEC511: Continuous Monitoring and Security Operations
- BTL1 / BTL2 by Security Blue Team - Very practical certs.
- Zero Point Security - Sentinel / DFIR Fundamentals
- CyberDefenders Bootcamp
- CyberDefenders - Blue Team CTFs - Dozens of free DFIR / SOC challenges.
- LetsDefend - guided SOC incidents
- TryHackMe SOC paths / Red-vs-Blue rooms
- Blue Team Labs Online
- RangeForce - Enterprise-grade blue-team labs.
- DetectionLab by Chris Long - Full AD + ELK + Velociraptor lab stack (note: archived 2023; see forks).
- SOC Simulator by SecurityBlueTeam
- HELK - Hunting ELK by Cyb3rWard0g
- Security Datasets project (Mordor) - Pre-recorded attack logs for practice.
- Splunk BOTS (Boss of the SOC) v1-v3 datasets
- APT Simulator - Quick IoC generation for detection testing.
- Splunk Enterprise Security / Splunk Free
- Microsoft Sentinel - Cloud-native SIEM with KQL.
- Elastic Security (ELK / Elastic Stack)
- Wazuh - Open-source SIEM/XDR.
- Graylog
- Google SecOps (Chronicle)
- IBM QRadar
- Sumo Logic
- CrowdStrike Falcon Next-Gen SIEM
- CrowdStrike Falcon
- Microsoft Defender for Endpoint
- SentinelOne
- Sysmon (open-source endpoint telemetry) - Use with SwiftOnSecurity's Sysmon config or Olaf Hartong's config.
- OSSEC / Wazuh agent
- osquery - SQL-based endpoint telemetry.
- Sigma - Vendor-neutral detection rule format.
- Elastic detection rules
- Splunk Security Content
- Azure Sentinel Community rules
- Atomic Red Team - Adversary test library; essential for detection validation.
- Red Canary Mac Monitor / Canary Tokens
- Zeek, Suricata, Snort 3
- Security Onion - Turnkey SOC distro.
- Arkime (formerly Moloch) - Full PCAP indexing.
- RITA by Active Countermeasures - Beacon / C2 analysis.
- Shuffle - Open-source SOAR.
- TheHive + Cortex - Case management + response.
- Tines / Torq - Commercial SOAR.
- Splunk SOAR (formerly Phantom)
- Jupyter notebooks + MSTICPy by Microsoft
- Hunting ELK (HELK)
- Velociraptor - Endpoint hunting & DFIR.
- KAPE by Eric Zimmerman
- BTL1 / BTL2 by Security Blue Team - Very respected practical certs.
- GCIA - GIAC Certified Intrusion Analyst (SANS)
- GCIH - GIAC Certified Incident Handler
- GMON - GIAC Continuous Monitoring Certification
- GCDA - GIAC Certified Detection Analyst
- CompTIA CySA+
- Microsoft SC-200 Security Operations Analyst
- Cisco CyberOps Associate / Professional
- Splunk Core / Splunk Enterprise Security certifications
- EC-Council CSA / CTIA
- HTB CDSA - Certified Defensive Security Analyst
- TCM Security PSAA - Practical SOC Analyst Associate
- MITRE ATT&CK - Technique reference every analyst should bookmark.
- MITRE D3FEND - Defensive techniques companion.
- The DFIR Report - Intrusion walk-throughs with IOCs and Sigma rules.
- Red Canary Threat Detection Report (annual)
- Microsoft Defender XDR / Sentinel blog
- SANS Internet Storm Center diary
- Pyramid of Pain - David Bianco
- Palantir Alerting and Detection Strategy framework
- Detection Engineering Cookbook
- Awesome SOC GitHub list
- Detection Engineering Weekly newsletter by Zack "techstackr" Allen
- Chris Sanders' blog (NSM, investigation theory)
- Anton Chuvakin's blog - SOC/SIEM research
- Florian Roth (Nextron) - detection research and YARA/Sigma rules
- OSSEM - Open Source Security Events Metadata