New: Roadmaps ordered paths through our cheat sheets and flashcards, so you always know what to study next.
Explore themSee what's new on GitHubFrom the CIA triad to running an incident from first alert to final report.
A 18-step learning path. Follow it in order, or jump to what you need.
For IT support staff, network admins, or complete career-changers aiming at a Security Operations Center seat, this is the blue-team, defense-first side of cybersecurity. Plan on about 10 weeks at a few hours a week, moving from core security concepts and networking through cryptography, SIEM, and threat intel to owning a full incident response. This path stays on defense: hands-on exploitation, recon, and attacker tooling belong to the Penetration Tester path, not here. By the end you can triage an alert in a SIEM, map an attacker's behavior to MITRE ATT&CK, and carry an incident from first detection through a compliance-ready report.
No prior experience needed. Start from zero.
Hands you the shared vocabulary, CIA triad, threat types, and controls, that every later step in this path assumes you already have.
This is where non-network folks usually stall; once packets, ports, and subnets click, every security tool downstream starts making sense.
Puts a terminal in your hands so you can follow the log analysis and SIEM work in section two instead of just reading about it.
You can talk security fundamentals and move around a Linux terminal without flinching. Next up: turning that footing into real network and identity defenses.
Finish this section to unlock.
+100 XP
Goes deeper on the network security basics step one only sketched, this time with firewalls, IDS/IPS, and segmentation you'll actually configure.
Breaks down the hashing and encryption that the IAM step next needs, so passwords and certificates stop feeling like magic.
Puts the crypto from step five to work deciding who gets in, MFA, SSO, and least privilege are the gatekeeping tools you'll audit for a living.
Turns the network and identity logs from the last three steps into a single console you can query when something looks wrong.
You can lock down a network, explain what a certificate actually buys you, and pull a SIEM query when something looks off. Next up: thinking like the adversary you're defending against.
Finish this section to unlock.
+100 XP
Alerts stop feeling random once you can place them on this map; expect to keep circling back to it as your reference framework for years.
Applies the ATT&CK tactics from step eight to an actual sample, so you can describe what a piece of malware is doing instead of just naming its family.
Reach for this if you're aiming at a senior or automation-heavy SOC seat: playbooks that fire your SIEM and IAM work from steps six and seven without a human clicking every time.
Shifts you from reacting to alerts toward reducing the attack surface before an attacker exploits what step nine's malware sample took advantage of.
Feeds the indicators and threat groups from ATT&CK and vulnerability data into a picture you can actually prioritize defenses around.
Fills your Tier 1 queue with the alert type you'll see daily, reading headers and red flags the way you read packets back in step two.
You can trace an attack through MITRE ATT&CK, catch a phishing email, and tell which vulnerabilities actually matter, and a few minutes of due flashcards keeps the SIEM skills from section two fresh while you build on them. Next up: compliance, forensics, and owning a full incident.
Finish this section to unlock.
+100 XP
Grab this if network architecture is where you're headed: zero trust replaces the perimeter model from step four with per-request verification everywhere.
Sets the reporting and audit language, ISO, SOC 2, GDPR, that the incident response step ahead needs to write a report someone outside the SOC can actually use.
Pick this up if your SOC covers cloud workloads: the shared-responsibility model changes what step four's firewalls and step six's IAM actually protect.
Preserves the evidence chain a court or auditor will ask about, the memory and disk artifacts you pull here are what the final incident report leans on.
Pulls every earlier step, SIEM alerts, ATT&CK mapping, forensics, and compliance reporting, into the one skill that actually defines the job: running an incident start to finish.
You can triage an alert, map it to ATT&CK, pull the forensic evidence, and write an incident report that satisfies both your team and an auditor. This badge marks you ready to sit a Tier 1-2 SOC analyst seat and keep learning from there.
Finish this section to unlock.
+100 XP
Finish every required step, at least 70% of them genuinely done (not skipped), to earn this badge and 500 XP.