
SOC Analyst Explores Detection Engineering Career Path
SOCDetectionEngineeringSplunkSysmonSigmaMITREATT&CKLOLBASRedCanaryAtomicRedTeam
The poster is a SOC L1 analyst with 1 year of experience and a prior background as a Network Security Engineer (3 years). They are exploring Detection Engineering as a career path, citing stagnation in their current role and a desire to learn new skills. Their current work involves Splunk and the Microsoft security stack, and they have set up a home lab with Splunk, Sysmon, and Sigma to practice writing detection rules. They follow a workflow of studying MITRE ATT&CK techniques, creating Sigma rules, converting them to Splunk alerts, and testing them using resources like LOLBAS, Red Canary, and Atomic Red Team.