Skip to content

From Zero to SOC Analyst: Complete Roadmap (2026)

Complete roadmap from zero to SOC analyst with free resources, certifications, and practical projects for 2026.

Key Takeaways

  • Strong IT and networking fundamentals are essential before diving into security.
  • Hands-on experience and projects are more valuable than just certifications.
  • AI skills are becoming critical for SOC analysts to stay competitive.
  • Free, high-quality resources are available to learn every phase of SOC analyst skills.
  • Certifications should be strategic and aligned with job market requirements.

What the video covers

  • Start with foundational IT knowledge including help desk basics, Linux, and Windows administration.
  • Build networking skills using free courses and hands-on emulators like Packet Tracer and GNS3.
  • Learn core security concepts such as the CIA triad, threat actors, and defense in depth.
  • Gain proficiency in SOC tools and workflows including Microsoft Sentinel, Splunk, and KQL.
  • Understand the growing role of AI in SOC workflows and learn how to effectively use AI tools.
  • Focus on key certifications: CompTIA Security+, Microsoft SC-200, and optionally CySA+ based on job market demand.
  • Prioritize hands-on projects and labs to build a portfolio that stands out to employers.
  • Join the My DFIR community for support, free guides, and networking with aspiring SOC analysts.
  • Avoid collecting random certifications; instead, build practical skills and relevant experience.
  • Use free platforms like TryHackMe, Hack The Box, and Security Blue Team for real-world SOC practice.

Answers

Questions about this video

What is the first step to becoming a SOC analyst according to the video?

The first step is to build a strong IT foundation including understanding help desk basics, Linux, and Windows administration before moving on to networking and security.

Which certifications does the video recommend for aspiring SOC analysts?

The video recommends starting with CompTIA Security+ and Microsoft SC-200, with CySA+ as an optional next step depending on job market demand.

How important are hands-on projects for SOC analyst candidates?

Hands-on projects are crucial and often differentiate candidates who get interviews from those who do not, as they demonstrate practical skills beyond certifications.

Full Transcript — Download SRT & Markdown

00:00
Speaker A
If you are starting from zero and you want to become a SOC analyst, you have probably been drowning in advice. Get the certification, watch this YouTube channel, learn this tool, take this course, and then you are right back
00:13
Speaker A
where you started, more confused than when you began. So, in this video, I am going to give you a complete roadmap from zero experience to SOC analyst ready. I will show you exactly what to learn, what order to learn it in, and
00:27
Speaker A
the free resources I would recommend at every single phase. This is a video I wish I had when I was starting out. If this is your first time seeing one of my videos, hello, my name is Steven, and
00:38
Speaker A
I've been working in cybersecurity for over a decade, mainly within the security operations domain. On this channel, you will find videos on career guidance, lab walkthroughs, and SOC-related projects that you can tackle and put on to your portfolio. I also run
00:53
Speaker A
a free community for aspiring SOC analysts like yourself, called the My IT for SOC community. So, if you want to be surrounded with like-minded individuals working towards the same goal, I would highly recommend checking it out. You will also find a free Kickstarter guide
01:08
Speaker A
in the community as well. The link will be in the description down below. So, the first phase of becoming a SOC analyst has nothing to do with cybersecurity, unfortunately. You need IT first, and I know that is not what most people want
01:21
Speaker A
to hear, especially if you have been watching cybersecurity videos for months, and you're itching to get into the cool stuff. But, hear me out. SOC analysts spend their days investigating activity on operating systems, networks, applications, and endpoints. If you do
01:36
Speaker A
not understand how any of these things work first, you cannot tell when something is wrong. You will be lost in your first week on the job, so that is why we start here. For the IT phase, the resources that I would recommend are all
01:49
Speaker A
free. TCM Security has a free practical help desk course that walks you through the basics of being a help desk technician. They also have a free Linux 100 fundamentals course that you absolutely need because as a SOC analyst, you will deal with Linux
02:04
Speaker A
systems constantly. For Windows, KevTech on YouTube has incredible free content. He walks through Active Directory, Windows Server Administration, all the practical stuff that you actually use on the job. And for the broader IT foundation, Professor Messer has a free
02:22
Speaker A
CompTIA A+ course on YouTube. The A+ is the IT generalist certification and even if you do not take the exam, which is optional by the way, the material covers everything from hardware to operating systems to troubleshooting. Once you
02:36
Speaker A
have the IT foundation, the next phase is networking. And honestly, this is the phase where most beginners struggle because networking just feels boring compared to learning a SIM or playing with malware. But networking is the language that all of those tools speak.
02:53
Speaker A
If you do not know networking, you cannot investigate a suspicious connection. For free networking resources, Professor Messer has a Network Plus course on YouTube. It covers OSI model, TCP/IP, routing, switching, all the fundamentals. For hands-on practice, you do have two free
03:10
Speaker A
options. GNS3 is a network emulator that lets you build virtual networks and configure devices. Packet Tracer is similar and is made by Cisco. Both are free. Either one will let you build networks and break them, which is way
03:23
Speaker A
more valuable than watching videos. Now, if you're wondering which one to pick first, well, Packet Tracer is easier to get into, at least in my opinion, but GNS3 is more powerful. So, I would start with Packet Tracer and then graduate to
03:38
Speaker A
GNS3 when you want more depth. Now, we get into security. This is the phase where you learn the core concepts that the rest of your career is going to build on. Things like the CIA triad, threat actors, attack types, defense in
03:51
Speaker A
depth, all of this stuff that shows up in every security conversation you will ever have. For free resources, you guessed it, Professor Messer comes back here with the Security+ course. Same format as the others, free YouTube playlist, study notes available on the
04:07
Speaker A
website, and the material is pretty solid. The other resource I would recommend is TCM Security's Practical Security Fundamentals course, as it is free and it covers similar material. And I would actually recommend doing both.
04:20
Speaker A
From here, you should have IT, networking, and security fundamentals. Now, you can start learning the tools and workflows that you will actually use on the job. For SIMs, specifically with Microsoft Sentinel, Microsoft has a free learning track called SC-200, which
04:37
Speaker A
covers Microsoft Sentinel, KQL, and Defender. It is on Microsoft Learn and is completely free. For Splunk, Cisco does offer a free career path that is available on their education portal that covers the basics and is called the Cybersecurity Defense Analyst path.
04:54
Speaker A
Security Blue Team also has free content that I would recommend. They have a free version of their introductory training that covers the basics of Blue Team work. And honestly, my channel does cover a lot of this, too. I have
05:07
Speaker A
walkthroughs on Sentinel, Splunk, Kaseya 7, KQL, and real investigation workflows. Now, I do want to talk about AI, and this is the section that is going to set you apart from a lot of the candidates who are applying to the same
05:21
Speaker A
SOC role that you are. AI is becoming part of the SOC analyst workflow, whether we like it or not. Tools are integrating it directly, and analysts who know how to use AI well are pulling ahead of analysts who do not. I've
05:34
Speaker A
actually created a video talking more about this topic, which you can find in the description. For free AI resources, TCM Security has an AI Fundamentals course, and it is a solid starting point. Anthropic has free courses on prompting and using AI tools
05:50
Speaker A
effectively. And Microsoft has an AI 901 certification track on Microsoft Learn, which is essentially their AI fundamentals path. Now, you do not need to be an AI expert, but what you do need to understand is how to use AI as a tool
06:06
Speaker A
to accelerate your work. Know how to write a good prompt, know when AI is wrong, and know how to verify an output.
06:13
Speaker A
Speaking of such, I do have a SOC automation project 2.0 on this channel that walks you through integrating Open AI directly into a SOC workflow. So, I would highly recommend checking that out if you want to put a pretty cool project
06:27
Speaker A
onto your portfolio. Now, let's talk about certifications. And I am going to be completely honest with you here because this is where a lot of money gets wasted. The certifications that I would actually recommend for someone starting out are CompTIA Security+ and
06:41
Speaker A
Microsoft SC-200. Security+ lets hiring managers know that you have foundational knowledge, whereas SC-200 lets them know that you have knowledge about the Microsoft security stack, which by the way a lot of SOCs have today. Now, I'm not a big fan of chasing certifications.
06:57
Speaker A
I would always rather see someone with hands-on experience and a real portfolio than someone with a stack of certificates.
07:04
Speaker A
But, I have to be honest with you about what I've been seeing in the job market lately. CompTIA CySA+ has been showing up more and more in SOC analyst job postings. So, if you are working through your certification and you are not sure
07:17
Speaker A
what comes after Security+, then CySA+ is worth considering. But, just know that you do not need all three right away. Start with Security+, add SC-200 when you're diving into Microsoft Sentinel, and then look into CySA+ if you are seeing it come up more in the
07:34
Speaker A
jobs that you are applying for. What I would not do is collect 10 random certifications hoping that one of them lands you a job. I mean, certifications can help you get past resume screening, but they do not get you the job, which
07:48
Speaker A
brings me to the next phase. Projects, in my opinion, is one of the biggest differences between candidates who get interviews and candidates who get ignored. The thre
08:00
Speaker A
The first is an active directory project. So, spin up a domain controller, create users, configure group policies, and then attack it. This teaches you how Windows environment actually look like and what suspicious activity looks like inside them. The
08:14
Speaker A
second is the SOC automation project. Build a small environment with a SIM and EDR and some kind of alerting pipeline.
08:21
Speaker A
Tools like Wazuh, Sentinel, and Splunk all have free options that work for this. Generate some attacks, watch them get detected, and then document what happened. The third is a SOAR EDR project. SOAR stands for security orchestration, automation, and response.
08:37
Speaker A
Build a small workflow that takes an alert from your EDR, and then enriches it with threat intelligence, and then either auto contains or escalate based off of the data. This right here is the kind of project that makes a hiring
08:50
Speaker A
manager go, "Oh, this person actually understands the workflow." Oh, and by the way, all three projects are inside my free community. Now, when you are doing these projects, be sure to document everything as you go. Take screenshots, write up what you found,
09:04
Speaker A
then put it on GitHub or LinkedIn. And that right there is your proof of work.
09:09
Speaker A
Alongside building up your own projects, you should also be working through hands-on labs that simulate real SOC work. Some of the free resources that you can use are TryHackMe, Hack The Box, Cyber Defenders, Security Blue Team, and Malware Traffic Analysis. If you work
09:25
Speaker A
through even half of these, you are going to be in a way better position than the average candidate applying for entry-level SOC roles. And that right there is the road map. We have IT fundamentals networking security fundamentals, SOC analyst skills, AI,
09:39
Speaker A
the right certifications, real projects, and hands-on labs. Just know that all of these free resources alone is going to take time. It takes discipline and it takes the ability to figure out what to do next when you get stuck. Now, before
09:54
Speaker A
I tell you about my paid option, I want to be very clear about something. The my D4 Forge is SOC analyst specific. So, if you are completely new to IT and you have not yet built up the foundations,
10:06
Speaker A
your first step is not the forge. Your first step is the IT, networking, and security fundamentals that I walked you through earlier in this video. Build those up first. Use the free resources that I listed and get comfortable with
10:19
Speaker A
the basics. Once you have those foundations down and you are in the position to invest, then the my D4 Forge could be your next step. The forge is an ongoing community built specifically for aspiring SOC analysts who are ready to
10:33
Speaker A
do the work. We have a structured 90-day SOC accelerator program that walks you through alert triage, investigations, and documentation step by step. We have a deeper course to level you up beyond what most entry-level training covers.
10:47
Speaker A
You get continued access to the SOC simulator with simulated clients including Splunk, Microsoft Sentinel, and Defender XDR. So, you are working with real alerts and we do run monthly capture the flag events. And you are also surrounded by a community of people
11:02
Speaker A
working towards the same goal as you. Now, the reason why I am positioning the forge the way I am is because working with real alerts on real enterprise tools is the true test of whether you are ready for the job. You can read
11:14
Speaker A
about SOC analyst work for years, but until you sit down and triage a real alert, you do not actually know if you can do it. The forge does give you that practice in a safe environment where you can make mistakes and then learn from
11:27
Speaker A
them before you ever set foot in a real SOC. But, at the end of the day, whatever path you pick, the most important thing is that you start and commit to it. That is it for the video and I hope that you found that
11:39
Speaker A
informative. If you did, let me know by hitting that like button and subscribe if you want to. Remember to stay curious and do things differently.
Topics:SOC analystcybersecurity careerIT fundamentalsnetworking basicssecurity conceptsMicrosoft SentinelSplunkAI in cybersecurityfree cybersecurity resourcesSOC analyst roadmap

Get More with the SozAI App

Transcribe recordings, audio files, and YouTube videos — with AI summaries, speaker detection, and unlimited transcriptions.

Or transcribe another YouTube video here →