Learning Paths
Learning path

SOC Analyst

Triage an alert to a decision, with the evidence written down, inside the time a real queue gives you.

Level
Beginner
Modules
5
Lessons
41
Time
38h

Built around the constraint that defines the job: a queue that does not stop. Every module ends in a decision with a stated confidence rather than in a conclusion, because that is the artifact a shift handover actually needs. Detection engineering is included from the start rather than treated as a senior-only topic, since an analyst who can write the rule is an analyst who understands why the alert fired.

Who it is for

Roles and prerequisites

Roles

  • SOC analyst
  • Incident responder
  • Detection engineer

Aligned with

  • CompTIA CySA+
  • Blue Team Level 1

Before you start

  • Basic networking: what a port, a DNS lookup and a TLS handshake are
  • Comfortable with a command line
Curriculum

The modules, in order

Order is the pedagogy here rather than a gate. Each module assumes the one before it.

  1. Where the evidence comes from

    Host, network, identity and cloud telemetry, what each one can and cannot tell you, and the gaps between them.

    8 lessons · 4h 30m

  2. Triage under load

    A method for the first five minutes of an alert that survives a queue depth of forty.

    7 lessons · 3h 0m

  3. Detection engineering

    Writing a Sigma rule that fires on the behaviour rather than on the artifact, and measuring what it costs in false positives.

    9 lessons · 4h 20m

  4. Attacker tradecraft, from the defender side

    Initial access, execution and persistence as they appear in logs, mapped to the techniques that produce them.

    12 lessons · 6h 30m · 1 lab

  5. Incident documentation

    Timeline, confidence statement, and the handover note. The part of the job that is graded after the incident.

    5 lessons · 2h 20m

Outcomes

What you will be able to do

  • Alert triage and prioritisation
  • Log analysis across host and network sources
  • Sigma rule authoring
  • Windows and Linux telemetry
  • Incident documentation
Concepts

Terms this path relies on

Free to read, no account needed. Worth skimming before module one.

Cyber VK Defensive Research

Pre-publication content owner

Internal ownership label for defensive-security material.

Technically reviewed by Cyber VK Security Curriculum

Updated

SOC Analyst Path · 1 Hands-On Lab · Cyber VK