// Phase 1 · Daily Study Plan · 2026

56 Days to
SOC Foundations

Every single day mapped out. What to watch, what to practise, what to build. No guesswork — just open this and do the day's tasks.

8 weeks
56 days planned
1.5–2 hrs weekdays
3–4 hrs weekends
$0 cost
How to use this: Each day has specific tasks. Tick them off as you go — your progress saves automatically. Weekend days are longer lab sessions. Every 7th day is review + rest. Consistency beats intensity — even 90 minutes a day adds up.
Days done
0
Tasks done
0
Total tasks
0
Overall progress — 0%
0
day streak
Recommended daily schedule
How to Structure Each Day
Two templates — pick the one that fits your schedule. The key is protecting your lab/practice time — that's where real learning happens.
📅 Weekday (1.5–2 hrs)
0–30 min
Watch
Video content
Professor Messer, NetworkChuck, or assigned YouTube. One concept at a time — don't rush.
30–80 min
Hands-on
Lab / TryHackMe / OverTheWire
Do the hands-on task for the day. This is the most important block — don't skip it for more videos.
80–100 min
Write
Notes + documentation
Write 3–5 bullet points of what you learned. Screenshot anything interesting. Future-you will thank you.
🗓️ Weekend (3–4 hrs)
0–45 min
Review
Review the week's notes
Re-read your notes from Mon–Fri. Quiz yourself on key concepts. Use Anki flashcards if you have them.
45–150 min
Deep lab
Extended lab session
Build, configure, break, fix. Wireshark captures, VM setup, Bandit wargame levels, THM rooms. Go deep.
150–210 min
Portfolio
Document + GitHub
Write up what you built. Push to GitHub. Add screenshots. This is your portfolio growing in real time.
210–240 min
Explore
Read / explore freely
Reddit r/cybersecurity, security blogs (Krebs on Security, SANS ISC), or a topic that caught your interest during the week.
Study tips that actually work
Make Every Session Count
🧠
Lab before you watch, not after
Try to do the lab task first, even blindly. Then watch the video. Struggling first makes the explanation stick 3× better.
✍️
Write it in your own words
After every session, explain the concept as if teaching a friend. If you can't explain it simply, you don't know it yet. Use Notion or a plain .md file.
🔁
Spaced repetition for ports & IDs
Use Anki (free) for memorising port numbers and Windows Event IDs. 5 minutes of flashcards daily beats cramming before interviews.
📸
Screenshot everything in the lab
Any time you see something interesting in Wireshark, Event Viewer, or a terminal — screenshot it. You'll use it in your GitHub write-ups later.
🚫
Skip the rabbit holes
When something interesting comes up mid-session, write it in a "rabbit hole list" and come back later. Staying on the day's plan is more valuable than depth-first tangents.
🔴
Don't break the chain
Even 20 minutes on a bad day beats zero. Watch a single Professor Messer video, do one Bandit level. The streak matters more than any single session.
💬
Use the TryHackMe Discord
When you're stuck on a room, the THM Discord has thousands of people who've done the same room. Ask. Getting unstuck fast matters more than solving everything alone.
📊
Track what you skip
If you skip a task, mark it with a note instead of just unchecking it. Pattern-matching your skipped tasks reveals what you're avoiding — which is usually what you most need to do.