This repository documents my learning journey toward becoming a Security Operations Center (SOC) analyst.
The focus is on defensive security fundamentals, alert triage, log analysis, incident investigations, and hands-on blue team labs.
All documentation is written as a personal learning record, emphasizing investigation logic, evidence analysis, and decision-making rather than step-by-step exploitation.
Industry frameworks referenced throughout this repository include:
- MITRE ATT&CK
- NIST Incident Response Lifecycle
The goal is to build strong analytical thinking and practical SOC skills through structured study and labs.