SOC Analyst
Triage an alert to a decision, with the evidence written down, inside the time a real queue gives you.
- Level
- Beginner
- Modules
- 5
- Lessons
- 41
- Time
- 38h
Built around the constraint that defines the job: a queue that does not stop. Every module ends in a decision with a stated confidence rather than in a conclusion, because that is the artifact a shift handover actually needs. Detection engineering is included from the start rather than treated as a senior-only topic, since an analyst who can write the rule is an analyst who understands why the alert fired.
Roles and prerequisites
Roles
- SOC analyst
- Incident responder
- Detection engineer
Aligned with
- CompTIA CySA+
- Blue Team Level 1
Before you start
- Basic networking: what a port, a DNS lookup and a TLS handshake are
- Comfortable with a command line
The modules, in order
Order is the pedagogy here rather than a gate. Each module assumes the one before it.
Where the evidence comes from
Host, network, identity and cloud telemetry, what each one can and cannot tell you, and the gaps between them.
8 lessons · 4h 30m
Triage under load
A method for the first five minutes of an alert that survives a queue depth of forty.
7 lessons · 3h 0m
Detection engineering
Writing a Sigma rule that fires on the behaviour rather than on the artifact, and measuring what it costs in false positives.
9 lessons · 4h 20m
Attacker tradecraft, from the defender side
Initial access, execution and persistence as they appear in logs, mapped to the techniques that produce them.
12 lessons · 6h 30m · 1 lab
Incident documentation
Timeline, confidence statement, and the handover note. The part of the job that is graded after the incident.
5 lessons · 2h 20m
What you will be able to do
- Alert triage and prioritisation
- Log analysis across host and network sources
- Sigma rule authoring
- Windows and Linux telemetry
- Incident documentation
Terms this path relies on
Free to read, no account needed. Worth skimming before module one.
Cyber VK Defensive Research
Pre-publication content owner
Internal ownership label for defensive-security material.
Technically reviewed by Cyber VK Security Curriculum
Updated
[ Related ]
- Learning pathBug Bounty Hunter pathPick a target, find a class of bug the automated scanners missed, and write it up so it gets triaged rather than closed.
- Learning pathWeb Application Penetration Tester pathTest a web application end to end and write a finding a developer can act on without asking you a follow-up question.