Home

rootuser.tech

My Journey to L2 SOC Analyst

From IT Support to Infrastructure Support to SOC

Documenting my growth through alert investigation, cloud and identity security, detection engineering, incident response, home lab work, and blue-team learning.

Current Focus

Security Operations With Infrastructure Context

SOC Investigations

Alert triage, evidence review, timelines, escalation notes, and incident documentation.

Cloud & Identity Security

Microsoft 365, Google Workspace, guest access, offboarding, sharing controls, and auditability.

Detection Engineering

SIEM queries, detection logic, MITRE ATT&CK mapping, false-positive review, and tuning notes.

Featured Work

Security Reviews and Lessons From the Field

Microsoft 365 Guest Access Security Baseline

A governance-focused review of external collaboration, anonymous sharing, guest access, and auditability.

Read writeup

Google Workspace Offboarding and Shared Files

Why suspending an account does not automatically remove external Drive sharing permissions.

Read writeup

Exchange Transport Rule for Phishing Patterns

Using a focused Exchange Online rule to reduce recurring phishing patterns while testing safely first.

Read writeup

Playbooks

Repeatable Analyst Workflows I Am Building

Phishing Investigation

Sender validation, link inspection, header review, attachment checks, user impact, and reporting steps.

Guest Access Review

External collaboration settings, sharing links, guest permissions, ownership, auditability, and risk acceptance.

Google Workspace Offboarding

Account suspension, session revocation, Drive ownership transfer, external sharing review, and retention checks.

Roadmap

The Path Toward L2 SOC

01

Document

Write clean investigation notes, case studies, and incident-style reports.

02

Detect

Create SIEM queries, detection ideas, MITRE mappings, and tuning notes.

03

Lab

Generate telemetry with Windows, Linux, Sysmon, authentication logs, and SIEM tools.

04

Grow

Build toward L2 SOC, detection engineering, incident response, and security operations engineering.