mars13-tech/free-soc-analyst-blue-team-resources

GitHub: mars13-tech/free-soc-analyst-blue-team-resources

该项目提供了一份100%免费的系统性学习路线图,整合了优质资源和动手实验,帮助零基础用户成长为具备入职能力的 SOC Analyst 或 Blue Team 专业人员。

Stars: 0 | Forks: 0

![SOC Analyst Banner](https://static.pigsec.cn/wp-content/uploads/repos/cas/9f/9f04a4bacdc097cc4ceafcd22b023d1dd4df9c70091d46b6cd392e86d088b195.png) # 🛡️ SOC Analyst 与 Blue Team 学习路线图 (100% 免费)
# 🚀 仅使用免费资源成为一名具备入职能力的 SOC Analyst 学习 Linux、网络、SIEM、Threat Hunting、Incident Response、Digital Forensics 和 Blue Team 操作,无需花费一分钱。 ![Free](https://img.shields.io/badge/Cost-100%25%20Free-brightgreen?style=for-the-badge) ![Role](https://img.shields.io/badge/Role-SOC%20Analyst-blue?style=for-the-badge) ![Focus](https://img.shields.io/badge/Focus-Blue%20Team-0A66C2?style=for-the-badge) ![Beginner](https://img.shields.io/badge/Beginner-Friendly-success?style=for-the-badge) ![Updated](https://img.shields.io/badge/Updated-July%202026-orange?style=for-the-badge)
# 📖 关于 本仓库包含了一系列精心挑选的**经过验证的免费**资源,适合任何准备从事以下职业的人: - 🛡️ SOC Analyst - 🔵 Blue Team Analyst - 🚨 Incident Responder - 🔍 Threat Hunter - 💻 安全运营工程师 无论你是从零开始还是正在准备面试,这份路线图都提供了你需要的一切——从 Linux 基础到构建你自己的家庭 SOC 实验室。 # 🎯 路线图 ``` 🐧 Linux │ ▼ 🌐 Networking │ ▼ 🔐 Security Fundamentals │ ▼ 📊 SIEM & Log Analysis │ ▼ 🖥️ Windows & Linux Investigation │ ▼ 🌍 Network Traffic Analysis │ ▼ 🔍 Threat Hunting │ ▼ 🚨 Incident Response │ ▼ 🛠️ Build Home Lab │ ▼ 💼 Portfolio │ ▼ 🎉 SOC Analyst ``` # 📚 目录 - Linux 基础 - 网络基础 - 动手实验室 - TryHackMe 学习路径 - 学习平台 - 练习日志与数据集 - 家庭实验室 - 作品集项目 - 建议学习路径 - 求职准备清单 # 🐧 Linux 基础 ## 🎯 目标 掌握每位 SOC Analyst 都需要的 Linux 命令行技能。 ## 📚 学习资源 | 资源 | 描述 | 链接 | |----------|-------------|------| | OverTheWire Bandit | Linux 命令行战争游戏 | https://overthewire.org/wargames/bandit/ | | Linux Journey | 交互式 Linux 课程 | https://linuxjourney.com/ | | ExplainShell | 解释每一个 Linux 命令 | https://explainshell.com/ | ## ✅ 你将学到的技能 - Linux CLI - SSH - 文件权限 - 用户与用户组 - grep - awk - sed - find - cron - Bash - 文件系统 - 进程 - 系统日志 ## 🏆 迷你项目 ✔ 仅使用终端导航 Linux ✔ 使用 grep 和 find 搜索文件 ✔ 通过 SSH 连接 ✔ 编写基本的 Bash 脚本 # 🌐 网络基础 ## 🎯 目标 了解计算机如何跨网络进行通信。 ## 📚 学习资源 | 资源 | 描述 | 链接 | |----------|-------------|------| | Professor Messer Network+ | 完整的网络课程 | https://www.professormesser.com/network-plus/n10-009/n10-009-video/n10-009-comptia-network-plus-course/ | | Cisco Networking Basics | 官方 Cisco 网络课程 | https://www.netacad.com/courses/networking-basics | | Practical Networking | TCP/IP 与路由教程 | https://www.practicalnetworking.net/ | | Subnetting Practice | 子网划分练习 | https://subnettingpractice.com/ | ## ✅ 你将学到的技能 - OSI 模型 - TCP/IP - IPv4 - IPv6 - DNS - DHCP - HTTP - HTTPS - FTP - SSH - SMTP - 防火墙 - NAT - VPN - 路由 - 交换 - VLAN - 子网划分 ## 🏆 迷你项目 ✔ 使用 Wireshark 捕获数据包 ✔ 识别 HTTP 请求 ✔ 识别 DNS 流量 ✔ 计算子网 # 🧪 动手实验室 | 平台 | 免费层级 | 最适合 | 链接 | |----------|-----------|----------|------| | LetsDefend | ✅ 15 个告警/月 | SOC 告警调查 | https://letsdefend.io/ | | TryHackMe | ✅ 部分免费 | 引导式 Blue Team 实验室 | https://tryhackme.com/ | | CyberDefenders | ✅ 是 | DFIR 与 Threat Hunting | https://cyberdefenders.org/blue-team-labs/ | | Blue Team Labs Online | ✅ 是 | 调查挑战 | https://blueteamlabs.online/ | | Security Onion | ✅ 是 | 家庭 SOC 平台 | https://github.com/Security-Onion-Solutions/securityonion | | Wazuh | ✅ 是 | SIEM + XDR | https://documentation.wazuh.com/current/quickstart.html | | DetectionLab | ✅ 是 | Active Directory 实验室 | https://github.com/clong/DetectionLab | | Splunk BOTS | ✅ 是 | Splunk Hunting 数据集 | https://github.com/splunk/botsv3 | # 🎯 你将练习什么 ✅ 告警分类 ✅ IOC 分析 ✅ Windows 日志调查 ✅ Linux 日志调查 ✅ PCAP 分析 ✅ 恶意软件分析 ✅ Threat Hunting ✅ Incident Response ✅ 检测工程 # 💡 推荐学习顺序 ``` 1️⃣ TryHackMe ↓ 2️⃣ LetsDefend ↓ 3️⃣ CyberDefenders ↓ 4️⃣ BTLO ↓ 5️⃣ DetectionLab ↓ 6️⃣ Wazuh ↓ 7️⃣ Security Onion ``` # 🧠 进度追踪器 | 阶段 | 状态 | |--------|--------| | Linux 基础 | ⬜ | | 网络基础 | ⬜ | | 安全基础 | ⬜ | | SIEM | ⬜ | | Windows 日志 | ⬜ | | Linux 日志 | ⬜ | | Threat Hunting | ⬜ | | Incident Response | ⬜ | | 家庭实验室 | ⬜ | | 作品集 | ⬜ | # 🚀 TryHackMe 学习路径 ## 🟢 第一阶段 — 基础 | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | SOC Role in Blue Team | SOC 基础 | https://tryhackme.com/room/socroleinblueteam | | ⬜ | Defensive Security Intro | Blue Team 基础 | https://tryhackme.com/room/defensivesecurityintroqW | | ⬜ | Intro to Logs | 日志分析 | https://tryhackme.com/room/introtologs | | ⬜ | Introduction to SIEM | SIEM 基础 | https://tryhackme.com/room/introtosiem | ### 🎯 你将获得的技能 - 了解 SOC Analyst 的角色 - 阅读和理解日志 - SIEM 基础 - Blue Team 工作流程 ## 🟢 第二阶段 — SIEM | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | Splunk: Exploring SPL | Splunk 搜索语言 | https://tryhackme.com/room/splunkexploringspl | ### 🎯 你将获得的技能 - SPL 查询 - 搜索日志 - 过滤事件 - 基础检测 ## 🟡 第三阶段 — Windows 日志分析 | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | Windows Logging for SOC | Windows 事件日志 | https://tryhackme.com/room/windowsloggingforsoc | | ⬜ | Investigating Windows | Windows 调查 | https://tryhackme.com/room/investigatingwindows | | ⬜ | Investigating Windows 2.0 | 高级调查 | https://tryhackme.com/room/investigatingwindows2 | | ⬜ | Windows Threat Detection 1 | 检测工程 | https://tryhackme.com/room/windowsthreatdetection1 | ### 🎯 你将获得的技能 - 事件查看器 - 事件 ID - Windows 安全日志 - PowerShell 日志 - Sysmon - 进程调查 ## 🟡 第四阶段 — Linux 日志分析 | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | Linux Logging for SOC | Linux 日志 | https://tryhackme.com/room/linuxloggingforsoc | | ⬜ | Linux Threat Detection 1 | 威胁检测 | https://tryhackme.com/room/linuxthreatdetection1 | | ⬜ | Linux Server Forensics | Linux DFIR | https://tryhackme.com/room/linuxserverforensics | ### 🎯 你将获得的技能 - Syslog - 身份验证日志 - 进程日志 - 服务日志 - Linux 调查 ## 🌐 第五阶段 — 网络流量分析 | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | Network Traffic Analysis Basics | 数据包分析 | https://tryhackme.com/room/networktrafficbasics | | ⬜ | TShark | CLI 数据包分析 | https://tryhackme.com/room/tshark | | ⬜ | Network Security Essentials | 网络安全 | https://tryhackme.com/room/networksecurityessentials | | ⬜ | Network Discovery Detection | 检测 | https://tryhackme.com/room/networkdiscoverydetection | | ⬜ | h4cked | 真实调查 | https://tryhackme.com/room/h4cked | | ⬜ | Event Horizon | SOC 调查 | https://tryhackme.com/room/eventhorizonroom | ### 🎯 你将获得的技能 - Wireshark - 数据包分析 - 网络 IOC 分析 - DNS 调查 - HTTP 分析 - 横向移动检测 ## 💻 第六阶段 — 端点检测与响应 (EDR) | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | Introduction to EDR | 端点安全 | https://tryhackme.com/room/introductiontoedrs | ### 🎯 你将获得的技能 - 端点监控 - EDR 概念 - 告警调查 - 端点遥测 ## 🔍 第七阶段 — Threat Hunting 与恶意软件分析 | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | Threat Hunting with YARA | YARA 规则 | https://tryhackme.com/room/threathuntingwithyara | | ⬜ | File and Hash Threat Intel | IOC 分析 | https://tryhackme.com/room/fileandhashthreatintel | | ⬜ | Volt Typhoon | APT 检测 | https://tryhackme.com/room/volttyphoon | ### 🎯 你将获得的技能 - YARA - IOC 分析 - 哈希分析 - 威胁情报 - APT 调查 ## 🚨 第八阶段 — Incident Response | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | IR Playbooks | Incident Response | https://tryhackme.com/room/irplaybooks | | ⬜ | SOC L1 Alert Reporting | 报告 | https://tryhackme.com/room/socl1alertreporting | | ⬜ | SOC L1 Alert Triage | 告警分类 | https://tryhackme.com/room/socl1alerttriage | | ⬜ | Identification & Scoping | 事件处理 | https://tryhackme.com/room/identificationandscoping | | ⬜ | AppSec IR | Web Incident Response | https://tryhackme.com/room/appsecir | | ⬜ | Detecting Web Attacks | Web 安全 | https://tryhackme.com/room/detectingwebattacks | | ⬜ | Chaining Vulnerabilities | 攻击链 | https://tryhackme.com/room/chainingvulnerabilitiesZp | ### 🎯 你将获得的技能 - Incident Response 生命周期 - 告警优先级排序 - 根本原因分析 - 报告 - 范围界定 - Web 攻击检测 ## 🏆 最终顶点挑战 | 状态 | 房间 | 技能 | 链接 | |--------|------|--------|------| | ⬜ | CCT2019 | 端到端 SOC 调查 | https://tryhackme.com/room/cct2019 | # 📊 总体进度 | 分类 | 房间数 | |----------|------:| | 🟢 基础 | 4 | | 📊 SIEM | 1 | | 🖥️ Windows 调查 | 4 | | 🐧 Linux 调查 | 3 | | 🌐 网络分析 | 6 | | 💻 端点检测 | 1 | | 🔍 Threat Hunting | 3 | | 🚨 Incident Response | | | 🏆 顶点 | 1 | ## ✅ TryHackMe 房间总数:**30** # 📚 学习平台 在你的动手实践之外,建立坚实的理论基础。 | 平台 | 描述 | 链接 | |----------|-------------|------| | Cybrary | 免费网络安全课程 | https://www.cybrary.it/ | | Cisco NetAcad – Introduction to Cybersecurity | 初学者课程 | https://www.netacad.com/courses/cybersecurity/introduction-cybersecurity | | Cisco NetAcad – CyberOps Associate | SOC Analyst 准备 | https://www.netacad.com/courses/cyberops-associate | | Professor Messer Security+ | 完整的 Security+ 课程 | https://www.professormesser.com/security-plus/sy0-701/sy0-701-video/sy0-701-comptia-security-plus-course/ | | Professor Messer Network+ | 完整的 Network+ 课程 | https://www.professormesser.com/network-plus/n10-009/n10-009-video/n10-009-comptia-network-plus-course/ | | MITRE ATT&CK | ATT&CK 框架 | https://attack.mitre.org/ | | ATT&CK Navigator | ATT&CK 可视化工具 | https://mitre-attack.github.io/attack-navigator/ | # 🗂️ 练习日志与数据集 使用真实世界的攻击数据进行练习。 | 数据集 | 描述 | 链接 | |----------|-------------|------| | Malware Traffic Analysis | 真实 PCAP 文件 | https://www.malware-traffic-analysis.net/ | | JPCERT EVTX ATTACK SAMPLES | Windows 事件日志 | https://github.com/JPCERTCC/EVTX-ATTACK-SAMPLES | | Splunk BOTS v3 | 企业攻击数据集 | https://github.com/splunk/botsv3 | | DetectionLab | Active Directory 检测实验室 | https://github.com/clong/DetectionLab | # 📝 博客与分析文章 了解专业人员如何调查事件。 | 博客 | 链接 | |------|------| | LetsDefend Blog | https://letsdefend.io/blog | | CyberDefenders Blog | https://cyberdefenders.org/blog/ | # 🛠️ 构建你自己的家庭 SOC 实验室 在学习了基础知识之后,构建你自己的 Blue Team 环境。 ## 选项 1 — Wazuh - 安装 Wazuh Server - 安装 Windows Agent - 安装 Linux Agent - 生成测试告警 - 调查事件 文档: https://documentation.wazuh.com/current/quickstart.html ## 选项 2 — Security Onion - 安装 Security Onion - 导入 PCAP 文件 - 分析 Zeek 日志 - 分析 Suricata 告警 - 创建仪表板 仓库: https://github.com/Security-Onion-Solutions/securityonion ## 选项 3 — DetectionLab - Active Directory - Splunk - Sysmon - Windows 域 - 攻击模拟 仓库: https://github.com/clong/DetectionLab # 💼 作品集项目 不要仅仅完成实验室——要展示你技能的证据。 ## 初学者 - [ ] Linux 命令笔记 - [ ] 网络笔记 - [ ] Windows 事件日志调查 - [ ] Linux 日志调查 - [ ] Wireshark 分析 ## 中级 - [ ] IOC 调查报告 - [ ] 钓鱼调查 - [ ] 恶意软件调查 - [ ] Splunk 仪表板 - [ ] Sigma 规则 - [ ] YARA 规则 - [ ] MITRE ATT&CK 映射 ## 高级 - [ ] 构建 DetectionLab - [ ] 部署 Wazuh - [ ] 部署 Security Onion - [ ] Threat Hunting 报告 - [ ] Incident Response 报告 - [ ] 检测工程项目 # 📂 推荐的 GitHub 仓库结构 ``` SOC-Analyst-Roadmap │ ├── Linux ├── Networking ├── TryHackMe ├── LetsDefend ├── CyberDefenders ├── Splunk ├── Wazuh ├── Security-Onion ├── DetectionLab ├── Sigma ├── YARA ├── Incident-Reports ├── Threat-Hunting ├── PCAP-Analysis ├── Malware-Analysis └── README.md ``` # 🏆 里程碑 ## 🥉 初学者 - Linux 基础 - 网络基础 - 安全基础 - 10 个 TryHackMe 房间 ## 🥈 中级 - 20+ 个 TryHackMe 房间 - 30 个 LetsDefend 告警 - 10 个 CyberDefenders 挑战 - 构建 Wazuh 实验室 ## 🥇 高级 - 构建 DetectionLab - Security Onion 实验室 - 发布 GitHub 作品集 - 发布 LinkedIn 分析文章 # 📅 建议的 24 周学习计划 | 周数 | 重点 | |--------|-------| | 1–2 | Linux | | 3–4 | 网络 | | 5 | Security+ 基础 | | 6–8 | SIEM | | 9–12 | Windows 日志 | | 13–14 | Linux 日志 | | 15–17 | 网络流量分析 | | 18–19 | Threat Hunting | | 20–21 | Incident Response | | 22–23 | 家庭实验室 | | 24 | 作品集与面试准备 | # 🎯 SOC Analyst 求职准备清单 ## 核心技能 - [ ] Linux - [ ] 网络 - [ ] Windows 事件日志 - [ ] Linux 日志 - [ ] Wireshark - [ ] Splunk - [ ] Wazuh - [ ] Security Onion - [ ] IOC 分析 - [ ] MITRE ATT&CK - [ ] Sigma 规则 - [ ] YARA 规则 - [ ] Threat Hunting - [ ] Incident Response ## 作品集 - [ ] GitHub 作品集 - [ ] 调查报告 - [ ] 检测规则 - [ ] 仪表板 - [ ] 家庭实验室 - [ ] LinkedIn 帖子 ## 面试准备 你应该能够自信地解释: - Windows 事件 ID - 身份验证日志 - PowerShell 日志 - Sysmon - SIEM 工作流程 - 告警分类 - MITRE ATT&CK - IOC 调查 - Incident Response 生命周期 - Threat Hunting 方法论 # 🌟 贡献 欢迎贡献! 如果你发现: - 失效的链接 - 过时的资源 - 更好的免费学习平台 - 新的 Blue Team 实验室 随时欢迎提交 Pull Request 或创建 Issue。 # ❤️ 支持 如果这个仓库帮助到了你: ⭐ 为仓库加星 🍴 Fork 该仓库 📢 与其他有志成为 SOC Analyst 的人分享 一起,我们可以让网络安全教育变得更加普及。 # 📄 许可证 本项目基于 **MIT License** 授权。 可出于教育目的自由使用、修改和分享。
## 🛡️ 祝 Hunting 愉快! **学习 • 练习 • 调查 • 检测 • 防御** 用 ❤️ 为网络安全社区制作。
标签:Burp Suite 替代, SOC分析, 学习路线, 安全, 库, 应急响应, 数字取证, 自动化脚本, 超时处理