Build SOC Analyst skills in 90 days.
Visit the MYDFIR Forge to find out how.


MyDFIR

Another MYDFIR Forge member landed the job đŸ”„

After years of trying to break into cybersecurity, they just received an offer for a Cyber Operations Analyst role.

What really stood out to me:
“Everything Steven teaches here aligns so well with the actual job responsibilities and the types of questions and scenarios you’ll encounter during an interview.”

This is why we focus so much on actually doing the work.

Huge congratulations on the new role!! 👏

18 hours ago | [YT] | 33

MyDFIR

MYDFIR SOC Investigation Cohort is LIVE

The job market is already difficult... Getting the interview is difficult.

So when you finally get that opportunity, I want you to be in the best position possible to take advantage of it.

When you finally get one, I don’t want: “Walk me through how you’d investigate this.” to be the question you weren’t prepared for.

That’s why I created the MYDFIR SOC Investigation Cohort.

For six weeks, we’re focusing on one thing: Investigations.

Every week, you’ll:

- See how I approach an investigation and the decisions behind it.
- Work through an investigation together.
- Take on an investigation yourself.
- Make decisions based on the evidence you have.
- Get direct feedback on your work.
- Write investigation reports.
- Explain and defend your conclusions...LIVE

Because knowing the tools is one thing.
Knowing what to do when the alert is yours is different.

The goal isn’t to memorize the right answer, It’s to learn how to find it.

So when someone asks you how you would approach an investigation, you’re not trying to remember something you watched in a course.

- You have actual reps behind your answer.
- You’ve investigated cases before.
- You’ve gotten stuck before.
- You’ve had your reasoning questioned before.
- You’ve written the report.
- You’ve defended your conclusion.
- And you’ve learned how to work through it.

And just as importantly, you’re building proof that you’ve done the work.

When an interviewer asks about your experience, you have investigations, reports, decisions, and examples you can actually speak to.

I’m accepting a maximum of 30 people because I need to be able to review your work, challenge your thinking, and give you meaningful feedback.

If investigations are the gap you’re trying to close, applications are now open!

APPLY HERE: mydfir.com/cohort

3 days ago | [YT] | 34

MyDFIR

You can’t control who else is interviewing

You might be competing against...

Someone with years of SOC experience.
Someone with a degree.
Someone with more certifications.

You can’t control that.

You can’t control how difficult the job market is either.

What you can control is how prepared you are when someone finally gives you the opportunity.

When they ask: “Walk me through how you would investigate this.”

Can you explain your thought process?
Can you tell them what you would look at first and why?
Can you scope beyond the alert?
Can you explain what the evidence supports and what it doesn’t?
Can you defend your conclusion when they start challenging your reasoning?

You may not be able to manufacture two years of professional SOC experience.

But you can build investigation reps.

You can have your reasoning challenged.
You can get direct feedback on where your investigation breaks down.
You can write investigation reports.
You can practice explaining and defending your decisions.

And you can repeat that process until you become less dependent on someone telling you what to do next.

That is exactly what I’m building the MYDFIR SOC Investigation Cohort around.

A premium 6-week hands-on program that is dedicated on teaching you one thing


How To Investigate.

This is not another SOC course that will teach you what a SIEM or EDR is.

This is a program that is designed to take you from "I don't know what to do with this alert" to "Give me the alert. I have a process for working through it." đŸ’Ș

1 week ago | [YT] | 60

MyDFIR

After 10 years in SecOps, this is what I’d focus on

I went from a Tier 1 analyst who questioned his own investigations to someone trusted to work through unfamiliar cases and train other analysts.

And one of the biggest things I’ve learned is this.

Knowing security is not the same as knowing how to investigate.

You can have certifications.
You can understand the tools.
You can complete labs.

But when someone asks

“Walk me through how you’d investigate this.”

Can you clearly explain what you would do?
Why you would do it?
What evidence you would want?
What would make you widen the scope?
What would change your conclusion?

And can you defend your decisions when they start pushing back?

That’s what I want to work on with 30 aspiring SOC analysts.

This will not be another broad SOC course.
This will be six weeks focused on investigations.

Applications opening soon!

Interested?

1 week ago | [YT] | 32

MyDFIR

I turned down a promotion because I didn’t trust myself

When I landed my first Tier 1 SOC analyst role, I thought getting the job meant I was ready.

I quickly realized I wasn’t. 😅

I received very little training. Everyone around me was busy trying to meet SLAs, asking for help wasn’t always easy, and I constantly questioned whether I was investigating things correctly.

When someone challenged my findings, I rarely felt confident defending my answer.

Eventually, I had an opportunity to move up to Tier 2...but I turned it down.

It wasn't because I didn’t want the opportunity, but because I was scared. I couldn’t see myself as a Tier 2 analyst nor did I think I was ready, and I didn’t tell anyone that was the real reason.

After that, whatever confidence I had left took a hit.
I had the job so many people were trying to get, yet I was sitting there wondering whether security operations was even the right path for me.

So I left the SOC and moved into vulnerability consulting because I thought maybe the pentesting route would suit me better, and this felt like the first step in that direction.

I did it for about a year...and I hated it.

Looking back, I hadn’t left because I suddenly discovered I wanted to become a pentester. I left because I didn’t trust myself as an investigator.

Eventually, I went back to security operations and started putting in the reps.

- More investigations.
- More mistakes.
- More questions.
- More responsibility for my own decisions.

Over time, things changed.

I soon became the person responsible for training other analysts. That experience shaped the way I teach cybersecurity today.

Knowing security concepts is one thing. Knowing what to do when an alert is yours, nobody is giving you the answer, and you have to defend your conclusion is something completely different.

A lot of what I’m building today comes directly from what I wish I had when I was that Tier 1 analyst questioning every decision I made.

2 weeks ago | [YT] | 76

MyDFIR

You finally get the SOC interview. Then they ask this


“Walk me through how you would investigate this.”

- What do you say?
- What would you look at first? Why?
- What would make you pivot?
- How far would you scope it?
- What evidence would support your conclusion?

That is where knowing SOC concepts and knowing how to investigate become two different things.

Another certification can give you more knowledge.

But eventually you need reps making investigative decisions, explaining those decisions, getting challenged on them, and doing it again.

The job market is already difficult enough.

When you finally get the opportunity, you want to be able to give it your best shot.

That’s the gap I’m working on solving
more details coming soon đŸ’Ș

2 weeks ago | [YT] | 60

MyDFIR

If your goal is to land your first SOC analyst role, what are you currently focusing on the most?

2 weeks ago | [YT] | 20

MyDFIR

Working on something new for aspiring SOC analysts who have spent months learning but still do not feel confident investigating when there is no walkthrough or answer key.

The goal...help you become the kind of analyst who can take an unfamiliar alert and know how to work the problem.

Who is interested?

4 weeks ago | [YT] | 204

MyDFIR

We got our first official giveaway entry in the books! As a reminder, 3 lucky winners will get 3 months of access to the MYDFIR Forge which will allow you to build some pretty sweet SOC skills.

Are you next? https://youtu.be/duEibRGYMHo

1 month ago | [YT] | 32

MyDFIR

How are you enjoying the Wazuh Challenge so far? I know we’re only on Day 2 of 7, but I’d love to hear your thoughts and feedback!

Are you also planning to enter the giveaway?

1 month ago | [YT] | 64