Learning Resources
Use primary vendor and standards sources first. Third-party videos or courses can help explain a topic, but the evidence should be grounded in the official documentation and the lab results.
Wazuh Documentation
Agents, manager, rules, decoders, alerts and platform operations.
Open Wazuh docs →Microsoft Windows Security
Windows security, auditing and endpoint telemetry references.
Open Windows security docs →Microsoft Sentinel
SIEM concepts, incidents, analytics rules and investigation workflows.
Open Sentinel docs →Cisco Skills for All
Networking and cybersecurity learning aligned to the existing Cisco foundation.
Open Cisco learning →Google Cybersecurity
Continue the concepts introduced by the existing Google Cybersecurity Professional Certificate.
Open Google cybersecurity →CompTIA Security+
Use the official exam/objective material as a broad junior-security knowledge framework.
Open Security+ →NIST Cybersecurity Framework
Risk and incident-response context for later roadmap stages.
Open NIST CSF →Resource map
| Capability | Primary references |
|---|---|
| Wazuh / SIEM | Wazuh documentation; Microsoft Sentinel documentation |
| Windows events | Microsoft Windows Security and auditing documentation |
| Networking | Cisco Skills for All / Networking Academy |
| Detection | Wazuh rules; MITRE ATT&CK; Sentinel analytics concepts |
| Incident response | CISA; NIST CSF |
| Cloud security | Google Cloud security docs; Microsoft/AWS security fundamentals as comparison |
| GitHub | GitHub Skills; GitHub Docs |
| Junior security breadth | CompTIA Security+ objectives |
Learning-to-evidence rule
For every learning resource, record:
- what was learned;
- which lab or project used it;
- what decision or investigation improved because of it;
- what remains uncertain.