mars13-tech/free-soc-analyst-blue-team-resources
GitHub: mars13-tech/free-soc-analyst-blue-team-resources
该项目提供了一份100%免费的系统性学习路线图,整合了优质资源和动手实验,帮助零基础用户成长为具备入职能力的 SOC Analyst 或 Blue Team 专业人员。
Stars: 0 | Forks: 0

# 🛡️ SOC Analyst 与 Blue Team 学习路线图 (100% 免费)
# 🚀 仅使用免费资源成为一名具备入职能力的 SOC Analyst
学习 Linux、网络、SIEM、Threat Hunting、Incident Response、Digital Forensics 和 Blue Team 操作,无需花费一分钱。





# 📖 关于
本仓库包含了一系列精心挑选的**经过验证的免费**资源,适合任何准备从事以下职业的人:
- 🛡️ SOC Analyst
- 🔵 Blue Team Analyst
- 🚨 Incident Responder
- 🔍 Threat Hunter
- 💻 安全运营工程师
无论你是从零开始还是正在准备面试,这份路线图都提供了你需要的一切——从 Linux 基础到构建你自己的家庭 SOC 实验室。
# 🎯 路线图
```
🐧 Linux
│
▼
🌐 Networking
│
▼
🔐 Security Fundamentals
│
▼
📊 SIEM & Log Analysis
│
▼
🖥️ Windows & Linux Investigation
│
▼
🌍 Network Traffic Analysis
│
▼
🔍 Threat Hunting
│
▼
🚨 Incident Response
│
▼
🛠️ Build Home Lab
│
▼
💼 Portfolio
│
▼
🎉 SOC Analyst
```
# 📚 目录
- Linux 基础
- 网络基础
- 动手实验室
- TryHackMe 学习路径
- 学习平台
- 练习日志与数据集
- 家庭实验室
- 作品集项目
- 建议学习路径
- 求职准备清单
# 🐧 Linux 基础
## 🎯 目标
掌握每位 SOC Analyst 都需要的 Linux 命令行技能。
## 📚 学习资源
| 资源 | 描述 | 链接 |
|----------|-------------|------|
| OverTheWire Bandit | Linux 命令行战争游戏 | https://overthewire.org/wargames/bandit/ |
| Linux Journey | 交互式 Linux 课程 | https://linuxjourney.com/ |
| ExplainShell | 解释每一个 Linux 命令 | https://explainshell.com/ |
## ✅ 你将学到的技能
- Linux CLI
- SSH
- 文件权限
- 用户与用户组
- grep
- awk
- sed
- find
- cron
- Bash
- 文件系统
- 进程
- 系统日志
## 🏆 迷你项目
✔ 仅使用终端导航 Linux
✔ 使用 grep 和 find 搜索文件
✔ 通过 SSH 连接
✔ 编写基本的 Bash 脚本
# 🌐 网络基础
## 🎯 目标
了解计算机如何跨网络进行通信。
## 📚 学习资源
| 资源 | 描述 | 链接 |
|----------|-------------|------|
| Professor Messer Network+ | 完整的网络课程 | https://www.professormesser.com/network-plus/n10-009/n10-009-video/n10-009-comptia-network-plus-course/ |
| Cisco Networking Basics | 官方 Cisco 网络课程 | https://www.netacad.com/courses/networking-basics |
| Practical Networking | TCP/IP 与路由教程 | https://www.practicalnetworking.net/ |
| Subnetting Practice | 子网划分练习 | https://subnettingpractice.com/ |
## ✅ 你将学到的技能
- OSI 模型
- TCP/IP
- IPv4
- IPv6
- DNS
- DHCP
- HTTP
- HTTPS
- FTP
- SSH
- SMTP
- 防火墙
- NAT
- VPN
- 路由
- 交换
- VLAN
- 子网划分
## 🏆 迷你项目
✔ 使用 Wireshark 捕获数据包
✔ 识别 HTTP 请求
✔ 识别 DNS 流量
✔ 计算子网
# 🧪 动手实验室
| 平台 | 免费层级 | 最适合 | 链接 |
|----------|-----------|----------|------|
| LetsDefend | ✅ 15 个告警/月 | SOC 告警调查 | https://letsdefend.io/ |
| TryHackMe | ✅ 部分免费 | 引导式 Blue Team 实验室 | https://tryhackme.com/ |
| CyberDefenders | ✅ 是 | DFIR 与 Threat Hunting | https://cyberdefenders.org/blue-team-labs/ |
| Blue Team Labs Online | ✅ 是 | 调查挑战 | https://blueteamlabs.online/ |
| Security Onion | ✅ 是 | 家庭 SOC 平台 | https://github.com/Security-Onion-Solutions/securityonion |
| Wazuh | ✅ 是 | SIEM + XDR | https://documentation.wazuh.com/current/quickstart.html |
| DetectionLab | ✅ 是 | Active Directory 实验室 | https://github.com/clong/DetectionLab |
| Splunk BOTS | ✅ 是 | Splunk Hunting 数据集 | https://github.com/splunk/botsv3 |
# 🎯 你将练习什么
✅ 告警分类
✅ IOC 分析
✅ Windows 日志调查
✅ Linux 日志调查
✅ PCAP 分析
✅ 恶意软件分析
✅ Threat Hunting
✅ Incident Response
✅ 检测工程
# 💡 推荐学习顺序
```
1️⃣ TryHackMe
↓
2️⃣ LetsDefend
↓
3️⃣ CyberDefenders
↓
4️⃣ BTLO
↓
5️⃣ DetectionLab
↓
6️⃣ Wazuh
↓
7️⃣ Security Onion
```
# 🧠 进度追踪器
| 阶段 | 状态 |
|--------|--------|
| Linux 基础 | ⬜ |
| 网络基础 | ⬜ |
| 安全基础 | ⬜ |
| SIEM | ⬜ |
| Windows 日志 | ⬜ |
| Linux 日志 | ⬜ |
| Threat Hunting | ⬜ |
| Incident Response | ⬜ |
| 家庭实验室 | ⬜ |
| 作品集 | ⬜ |
# 🚀 TryHackMe 学习路径
## 🟢 第一阶段 — 基础
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | SOC Role in Blue Team | SOC 基础 | https://tryhackme.com/room/socroleinblueteam |
| ⬜ | Defensive Security Intro | Blue Team 基础 | https://tryhackme.com/room/defensivesecurityintroqW |
| ⬜ | Intro to Logs | 日志分析 | https://tryhackme.com/room/introtologs |
| ⬜ | Introduction to SIEM | SIEM 基础 | https://tryhackme.com/room/introtosiem |
### 🎯 你将获得的技能
- 了解 SOC Analyst 的角色
- 阅读和理解日志
- SIEM 基础
- Blue Team 工作流程
## 🟢 第二阶段 — SIEM
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | Splunk: Exploring SPL | Splunk 搜索语言 | https://tryhackme.com/room/splunkexploringspl |
### 🎯 你将获得的技能
- SPL 查询
- 搜索日志
- 过滤事件
- 基础检测
## 🟡 第三阶段 — Windows 日志分析
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | Windows Logging for SOC | Windows 事件日志 | https://tryhackme.com/room/windowsloggingforsoc |
| ⬜ | Investigating Windows | Windows 调查 | https://tryhackme.com/room/investigatingwindows |
| ⬜ | Investigating Windows 2.0 | 高级调查 | https://tryhackme.com/room/investigatingwindows2 |
| ⬜ | Windows Threat Detection 1 | 检测工程 | https://tryhackme.com/room/windowsthreatdetection1 |
### 🎯 你将获得的技能
- 事件查看器
- 事件 ID
- Windows 安全日志
- PowerShell 日志
- Sysmon
- 进程调查
## 🟡 第四阶段 — Linux 日志分析
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | Linux Logging for SOC | Linux 日志 | https://tryhackme.com/room/linuxloggingforsoc |
| ⬜ | Linux Threat Detection 1 | 威胁检测 | https://tryhackme.com/room/linuxthreatdetection1 |
| ⬜ | Linux Server Forensics | Linux DFIR | https://tryhackme.com/room/linuxserverforensics |
### 🎯 你将获得的技能
- Syslog
- 身份验证日志
- 进程日志
- 服务日志
- Linux 调查
## 🌐 第五阶段 — 网络流量分析
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | Network Traffic Analysis Basics | 数据包分析 | https://tryhackme.com/room/networktrafficbasics |
| ⬜ | TShark | CLI 数据包分析 | https://tryhackme.com/room/tshark |
| ⬜ | Network Security Essentials | 网络安全 | https://tryhackme.com/room/networksecurityessentials |
| ⬜ | Network Discovery Detection | 检测 | https://tryhackme.com/room/networkdiscoverydetection |
| ⬜ | h4cked | 真实调查 | https://tryhackme.com/room/h4cked |
| ⬜ | Event Horizon | SOC 调查 | https://tryhackme.com/room/eventhorizonroom |
### 🎯 你将获得的技能
- Wireshark
- 数据包分析
- 网络 IOC 分析
- DNS 调查
- HTTP 分析
- 横向移动检测
## 💻 第六阶段 — 端点检测与响应 (EDR)
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | Introduction to EDR | 端点安全 | https://tryhackme.com/room/introductiontoedrs |
### 🎯 你将获得的技能
- 端点监控
- EDR 概念
- 告警调查
- 端点遥测
## 🔍 第七阶段 — Threat Hunting 与恶意软件分析
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | Threat Hunting with YARA | YARA 规则 | https://tryhackme.com/room/threathuntingwithyara |
| ⬜ | File and Hash Threat Intel | IOC 分析 | https://tryhackme.com/room/fileandhashthreatintel |
| ⬜ | Volt Typhoon | APT 检测 | https://tryhackme.com/room/volttyphoon |
### 🎯 你将获得的技能
- YARA
- IOC 分析
- 哈希分析
- 威胁情报
- APT 调查
## 🚨 第八阶段 — Incident Response
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | IR Playbooks | Incident Response | https://tryhackme.com/room/irplaybooks |
| ⬜ | SOC L1 Alert Reporting | 报告 | https://tryhackme.com/room/socl1alertreporting |
| ⬜ | SOC L1 Alert Triage | 告警分类 | https://tryhackme.com/room/socl1alerttriage |
| ⬜ | Identification & Scoping | 事件处理 | https://tryhackme.com/room/identificationandscoping |
| ⬜ | AppSec IR | Web Incident Response | https://tryhackme.com/room/appsecir |
| ⬜ | Detecting Web Attacks | Web 安全 | https://tryhackme.com/room/detectingwebattacks |
| ⬜ | Chaining Vulnerabilities | 攻击链 | https://tryhackme.com/room/chainingvulnerabilitiesZp |
### 🎯 你将获得的技能
- Incident Response 生命周期
- 告警优先级排序
- 根本原因分析
- 报告
- 范围界定
- Web 攻击检测
## 🏆 最终顶点挑战
| 状态 | 房间 | 技能 | 链接 |
|--------|------|--------|------|
| ⬜ | CCT2019 | 端到端 SOC 调查 | https://tryhackme.com/room/cct2019 |
# 📊 总体进度
| 分类 | 房间数 |
|----------|------:|
| 🟢 基础 | 4 |
| 📊 SIEM | 1 |
| 🖥️ Windows 调查 | 4 |
| 🐧 Linux 调查 | 3 |
| 🌐 网络分析 | 6 |
| 💻 端点检测 | 1 |
| 🔍 Threat Hunting | 3 |
| 🚨 Incident Response | |
| 🏆 顶点 | 1 |
## ✅ TryHackMe 房间总数:**30**
# 📚 学习平台
在你的动手实践之外,建立坚实的理论基础。
| 平台 | 描述 | 链接 |
|----------|-------------|------|
| Cybrary | 免费网络安全课程 | https://www.cybrary.it/ |
| Cisco NetAcad – Introduction to Cybersecurity | 初学者课程 | https://www.netacad.com/courses/cybersecurity/introduction-cybersecurity |
| Cisco NetAcad – CyberOps Associate | SOC Analyst 准备 | https://www.netacad.com/courses/cyberops-associate |
| Professor Messer Security+ | 完整的 Security+ 课程 | https://www.professormesser.com/security-plus/sy0-701/sy0-701-video/sy0-701-comptia-security-plus-course/ |
| Professor Messer Network+ | 完整的 Network+ 课程 | https://www.professormesser.com/network-plus/n10-009/n10-009-video/n10-009-comptia-network-plus-course/ |
| MITRE ATT&CK | ATT&CK 框架 | https://attack.mitre.org/ |
| ATT&CK Navigator | ATT&CK 可视化工具 | https://mitre-attack.github.io/attack-navigator/ |
# 🗂️ 练习日志与数据集
使用真实世界的攻击数据进行练习。
| 数据集 | 描述 | 链接 |
|----------|-------------|------|
| Malware Traffic Analysis | 真实 PCAP 文件 | https://www.malware-traffic-analysis.net/ |
| JPCERT EVTX ATTACK SAMPLES | Windows 事件日志 | https://github.com/JPCERTCC/EVTX-ATTACK-SAMPLES |
| Splunk BOTS v3 | 企业攻击数据集 | https://github.com/splunk/botsv3 |
| DetectionLab | Active Directory 检测实验室 | https://github.com/clong/DetectionLab |
# 📝 博客与分析文章
了解专业人员如何调查事件。
| 博客 | 链接 |
|------|------|
| LetsDefend Blog | https://letsdefend.io/blog |
| CyberDefenders Blog | https://cyberdefenders.org/blog/ |
# 🛠️ 构建你自己的家庭 SOC 实验室
在学习了基础知识之后,构建你自己的 Blue Team 环境。
## 选项 1 — Wazuh
- 安装 Wazuh Server
- 安装 Windows Agent
- 安装 Linux Agent
- 生成测试告警
- 调查事件
文档:
https://documentation.wazuh.com/current/quickstart.html
## 选项 2 — Security Onion
- 安装 Security Onion
- 导入 PCAP 文件
- 分析 Zeek 日志
- 分析 Suricata 告警
- 创建仪表板
仓库:
https://github.com/Security-Onion-Solutions/securityonion
## 选项 3 — DetectionLab
- Active Directory
- Splunk
- Sysmon
- Windows 域
- 攻击模拟
仓库:
https://github.com/clong/DetectionLab
# 💼 作品集项目
不要仅仅完成实验室——要展示你技能的证据。
## 初学者
- [ ] Linux 命令笔记
- [ ] 网络笔记
- [ ] Windows 事件日志调查
- [ ] Linux 日志调查
- [ ] Wireshark 分析
## 中级
- [ ] IOC 调查报告
- [ ] 钓鱼调查
- [ ] 恶意软件调查
- [ ] Splunk 仪表板
- [ ] Sigma 规则
- [ ] YARA 规则
- [ ] MITRE ATT&CK 映射
## 高级
- [ ] 构建 DetectionLab
- [ ] 部署 Wazuh
- [ ] 部署 Security Onion
- [ ] Threat Hunting 报告
- [ ] Incident Response 报告
- [ ] 检测工程项目
# 📂 推荐的 GitHub 仓库结构
```
SOC-Analyst-Roadmap
│
├── Linux
├── Networking
├── TryHackMe
├── LetsDefend
├── CyberDefenders
├── Splunk
├── Wazuh
├── Security-Onion
├── DetectionLab
├── Sigma
├── YARA
├── Incident-Reports
├── Threat-Hunting
├── PCAP-Analysis
├── Malware-Analysis
└── README.md
```
# 🏆 里程碑
## 🥉 初学者
- Linux 基础
- 网络基础
- 安全基础
- 10 个 TryHackMe 房间
## 🥈 中级
- 20+ 个 TryHackMe 房间
- 30 个 LetsDefend 告警
- 10 个 CyberDefenders 挑战
- 构建 Wazuh 实验室
## 🥇 高级
- 构建 DetectionLab
- Security Onion 实验室
- 发布 GitHub 作品集
- 发布 LinkedIn 分析文章
# 📅 建议的 24 周学习计划
| 周数 | 重点 |
|--------|-------|
| 1–2 | Linux |
| 3–4 | 网络 |
| 5 | Security+ 基础 |
| 6–8 | SIEM |
| 9–12 | Windows 日志 |
| 13–14 | Linux 日志 |
| 15–17 | 网络流量分析 |
| 18–19 | Threat Hunting |
| 20–21 | Incident Response |
| 22–23 | 家庭实验室 |
| 24 | 作品集与面试准备 |
# 🎯 SOC Analyst 求职准备清单
## 核心技能
- [ ] Linux
- [ ] 网络
- [ ] Windows 事件日志
- [ ] Linux 日志
- [ ] Wireshark
- [ ] Splunk
- [ ] Wazuh
- [ ] Security Onion
- [ ] IOC 分析
- [ ] MITRE ATT&CK
- [ ] Sigma 规则
- [ ] YARA 规则
- [ ] Threat Hunting
- [ ] Incident Response
## 作品集
- [ ] GitHub 作品集
- [ ] 调查报告
- [ ] 检测规则
- [ ] 仪表板
- [ ] 家庭实验室
- [ ] LinkedIn 帖子
## 面试准备
你应该能够自信地解释:
- Windows 事件 ID
- 身份验证日志
- PowerShell 日志
- Sysmon
- SIEM 工作流程
- 告警分类
- MITRE ATT&CK
- IOC 调查
- Incident Response 生命周期
- Threat Hunting 方法论
# 🌟 贡献
欢迎贡献!
如果你发现:
- 失效的链接
- 过时的资源
- 更好的免费学习平台
- 新的 Blue Team 实验室
随时欢迎提交 Pull Request 或创建 Issue。
# ❤️ 支持
如果这个仓库帮助到了你:
⭐ 为仓库加星
🍴 Fork 该仓库
📢 与其他有志成为 SOC Analyst 的人分享
一起,我们可以让网络安全教育变得更加普及。
# 📄 许可证
本项目基于 **MIT License** 授权。
可出于教育目的自由使用、修改和分享。
## 🛡️ 祝 Hunting 愉快!
**学习 • 练习 • 调查 • 检测 • 防御**
用 ❤️ 为网络安全社区制作。
标签:Burp Suite 替代, SOC分析, 学习路线, 安全, 库, 应急响应, 数字取证, 自动化脚本, 超时处理