🔄 Topic

Consolidating Course 2 into practical portfolio artifacts: audit notes, SIEM triage, playbooks, and risk language.


🎯 Goal

Turn risk-management course material into credible public documentation without sounding like copied course notes.


🛠 What I Did

Today I consolidated the main work from Course 2 — Play It Safe: Manage Security Risks.

The strongest portfolio opportunities from this course are not the definitions. They are the activities and workflows:

  • threat/risk/vulnerability classification
  • security audit findings
  • control reviews
  • SIEM alert triage
  • playbook-based response
  • clear documentation of evidence and impact

This is where broad course theory starts becoming useful public proof of work.


🔗 Key Cybersecurity Connections

A certificate says I studied something. A portfolio artifact shows how I think.

A weak blog post says:

I learned about SIEM and playbooks.

A stronger artifact shows:

alert evidence, triage questions, false-positive checks, escalation logic, impact, and recommended next action.

This difference is important for employability because hiring managers need evidence that I can reason through a security problem.


🔍 Investigation Questions

  • Can this topic become a realistic mini-case?
  • What evidence would I include?
  • What logs or screenshots would make it credible?
  • What decision did the analyst make?
  • What false positives were considered?
  • What control failed or worked?
  • What should be improved after the incident?

🚨 Detection Opportunities

Portfolio-worthy detection/reporting ideas:

  • password spray triage report
  • phishing playbook
  • security audit finding
  • SIEM dashboard explanation
  • control failure mapped to risk
  • incident response timeline

Example artifact structure:

scenario
evidence
triage questions
detection logic
false positives
severity
response steps
lessons learned

🧭 MITRE ATT&CK Techniques

Possible ATT&CK mappings depend on the scenario selected:

  • T1566 — Phishing
  • T1110.003 — Password Spraying
  • T1078 — Valid Accounts
  • T1562 — Impair Defenses
  • T1490 — Inhibit System Recovery

🗺 Visual Investigation Diagram

Course concept
    ↓
Realistic scenario
    ↓
Logs / evidence
    ↓
Triage workflow
    ↓
Detection or playbook
    ↓
Portfolio artifact

⚠ Challenges

The challenge is avoiding generic certificate summaries. Public blog posts should not read like course recaps only.

They need to show practical judgement: what I would check, what evidence matters, what mistakes I would avoid, and how I would respond.


📚 What I Learned

I learned that Course 2 gives useful SOC structure if I convert it properly. Risk management, SIEM, and playbooks are directly connected to analyst work.


➡ Next Steps

  • Turn one Course 2 topic into a polished GitHub artifact
  • Create a reusable incident triage template
  • Write one playbook in a practical format
  • Use risk/control/evidence language consistently

🧠 Reflection

This was a good checkpoint. I can now explain risk more professionally and connect it to SOC operations.


🧩 Lessons Learned

What worked

Focusing on artifacts instead of course completion.

What broke

Generic summaries do not prove skill.

Why it broke

Anyone can say they learned a concept; fewer people show how they would use it.

Fix / takeaway

Every blog post should include scenario, evidence, decision points, and defender value.


📈 Skill Progression Context

This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.

Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.


😄 TL;DR

The certificate is learning. The portfolio is proof.