rootuser.tech
My Journey to L2 SOC Analyst
From IT Support to Infrastructure Support to SOC
Documenting my growth through alert investigation, cloud and identity security, detection engineering, incident response, home lab work, and blue-team learning.
Current Focus
Security Operations With Infrastructure Context
SOC Investigations
Alert triage, evidence review, timelines, escalation notes, and incident documentation.
Cloud & Identity Security
Microsoft 365, Google Workspace, guest access, offboarding, sharing controls, and auditability.
Detection Engineering
SIEM queries, detection logic, MITRE ATT&CK mapping, false-positive review, and tuning notes.
Featured Work
Security Reviews and Lessons From the Field
Microsoft 365 Guest Access Security Baseline
A governance-focused review of external collaboration, anonymous sharing, guest access, and auditability.
Read writeupGoogle Workspace Offboarding and Shared Files
Why suspending an account does not automatically remove external Drive sharing permissions.
Read writeupExchange Transport Rule for Phishing Patterns
Using a focused Exchange Online rule to reduce recurring phishing patterns while testing safely first.
Read writeupPlaybooks
Repeatable Analyst Workflows I Am Building
Phishing Investigation
Sender validation, link inspection, header review, attachment checks, user impact, and reporting steps.
Guest Access Review
External collaboration settings, sharing links, guest permissions, ownership, auditability, and risk acceptance.
Google Workspace Offboarding
Account suspension, session revocation, Drive ownership transfer, external sharing review, and retention checks.
Roadmap
The Path Toward L2 SOC
Document
Write clean investigation notes, case studies, and incident-style reports.
Detect
Create SIEM queries, detection ideas, MITRE mappings, and tuning notes.
Lab
Generate telemetry with Windows, Linux, Sysmon, authentication logs, and SIEM tools.
Grow
Build toward L2 SOC, detection engineering, incident response, and security operations engineering.