12-Month Roadmap
| Phase | Months | Focus | Required outcome |
|---|---|---|---|
| Foundation | 1–2 | Windows telemetry, networking, Wazuh, GitHub workflow | Reliable alert triage and evidence habits |
| Detection & IR | 3–4 | Detection logic, ATT&CK, incident response, threat intelligence | Detection pack + incident runbook |
| Cloud & automation | 5–6 | Cloud-security fundamentals, Python/PowerShell basics, GitHub Actions | Cloud baseline + small automation artefact |
| SOC depth | 7–8 | Threat hunting, rule tuning, case management, reporting | Multi-stage investigation portfolio |
| Professional growth | 9–10 | Communication, interview preparation, cross-functional work | Interview-ready CV/LinkedIn/portfolio evidence |
| Specialisation | 11–12 | Detection engineering, cloud security or incident response | Capstone and next-role development plan |
Months 1–2 — Foundation
- establish a repeatable Windows-event investigation method;
- strengthen TCP/IP, DNS, authentication and endpoint-log reasoning;
- understand Wazuh agent, manager, rules, alerts and decoder concepts;
- use GitHub issues, branches, commits and README files professionally;
- complete the 12-week sprint with evidence rather than attendance.
Months 3–4 — Detection and incident response
- write and test simple detection logic;
- document false positives and tuning decisions;
- map common activity to MITRE ATT&CK;
- complete incident-response tabletop exercises;
- improve incident summaries and escalation writing.
Months 5–6 — Cloud and automation
- learn identity, least privilege, logging, monitoring and network controls in cloud environments;
- compare cloud controls across Google Cloud, Microsoft Azure and AWS at a fundamentals level;
- automate one repeatable SOC task with Python or PowerShell;
- add automated validation to a GitHub repository.
Months 7–8 — SOC depth
- run multi-source investigations;
- practise threat hunting from a hypothesis rather than an alert;
- create a small SOC scorecard;
- improve Wazuh rules and documentation;
- produce a case-study style investigation.
Months 9–10 — Professional growth
- refine CV, LinkedIn and GitHub portfolio around evidence;
- practise concise written and verbal incident explanations;
- complete mock SOC interviews;
- participate in a cross-functional or peer-review activity;
- improve time-management habits around focused learning blocks.
Months 11–12 — Specialisation
Choose one primary direction based on evidence and opportunity:
- Detection Engineering;
- Cloud Security;
- Incident Response / Threat Hunting.
Complete a capstone that combines telemetry, detection, investigation, documentation and presentation.
Formal gates
- Day 30: evidence workflow and first Windows/Wazuh investigations are reliable.
- Day 60: at least one detection and one incident-response artefact are mentor-reviewed.
- Day 90: at least 10 sprint weeks are accepted and three portfolio artefacts are review-ready.
- Month 6: one automation and one cloud-security artefact are complete.
- Month 12: six portfolio items and a capstone support a clear next-role story.