Cyber Foundations
The starting point before SOC Analyst L1 — what cybersecurity actually protects, and the vocabulary every later module builds on.
What you will be able to do
- Explain what cybersecurity protects and why it is a shared responsibility, not one tool.
- Identify digital assets, threats, attackers and defenders in a real scenario.
Units
- 01
Digital & Cybersecurity Foundations
What cybersecurity means, what a digital environment is made of, and the four ideas — asset, threat, attacker, defender — every later module assumes you already know.
BeginnerAvailableWhy you are learning this
Every SOC module that follows talks about protecting assets from threat actors. This module is where those words stop being jargon and start being tools you use on purpose.
- 02
Networking Foundations
How networks actually move data — addressing, TCP/UDP and ports, DNS/DHCP/HTTP, switching and routing, and the controls that defend a network — the vocabulary every later network investigation assumes.
BeginnerAvailableWhy you are learning this
Nearly every SOC and Tool Academy module that follows reads network evidence — an IP, a port, a DNS name. This module is where that evidence stops being unfamiliar.
Unit contents9
Theory Lessons(8)
Practical Labs(1)
- 03
Operating Systems & Endpoint Foundations
What an operating system actually coordinates — users, processes, services, files and network activity — on both Windows and Linux, and how that activity becomes the telemetry a SOC reviews.
BeginnerAvailableWhy you are learning this
Almost every host investigation is really a question about processes, files and connections on an endpoint. This module builds the vocabulary that makes an event log readable instead of noise.
Unit contents10
Theory Lessons(9)
Operating System Fundamentals
Theory+40 XPWindows Fundamentals
Theory+40 XPLinux Fundamentals
Theory+40 XPUsers, Groups & Permissions
Theory+40 XPProcesses & Services
Theory+40 XPFiles & Network Connections
Theory+40 XPEndpoint Security
Theory+40 XPLogs & Telemetry Introduction
Theory+40 XPEndpoint Foundations Review
Theory+40 XP
Practical Labs(1)
- 04
Identity, Access & Cryptography
Who a system believes you are, what it then lets you do, and how encryption, hashing and certificates protect and prove that relationship.
BeginnerAvailableWhy you are learning this
Identity is the thread through nearly every investigation — a compromised account, a misused privilege, a certificate nobody trusts. This module builds that vocabulary before it is needed under pressure.
Unit contents10
Theory Lessons(9)
Identity & Access Fundamentals
Theory+40 XPAuthentication vs Authorization
Theory+40 XPPasswords & Multi-Factor Authentication
Theory+40 XPAccounts, Roles & Privileges
Theory+40 XPEncryption Fundamentals
Theory+40 XPSymmetric vs Asymmetric Encryption
Theory+40 XPHashing vs Encryption vs Encoding
Theory+40 XPDigital Signatures, Certificates & PKI
Theory+40 XPIdentity & Cryptography Review
Theory+40 XP
Practical Labs(1)
- 05
Threats & Attacks
Who attacks organizations and why, and how phishing, credential attacks, malware, network attacks, web threats and denial of service actually work at a foundational level.
BeginnerAvailableWhy you are learning this
Every alert a SOC analyst triages is a suspected instance of something in this module. Recognizing the pattern is what turns a wall of alerts into a manageable queue.
Unit contents10
Theory Lessons(9)
Threat Actors & Motivations
Theory+40 XPSocial Engineering & Phishing
Theory+40 XPCredential & Password Attacks
Theory+40 XPMalware Fundamentals
Theory+40 XPNetwork Attacks
Theory+40 XPWeb Application Threats
Theory+40 XPDenial of Service — DoS & DDoS
Theory+40 XPInsider Threats, Zero-Days & Emerging Threats
Theory+40 XPThreats & Attacks Review
Theory+40 XP
Practical Labs(1)
- 06
Security Operations Foundations
How a SOC actually works — telemetry, logs, SIEM, detection logic, alert triage, incident response, and the frameworks analysts use to turn observations into a coordinated response.
BeginnerAvailableWhy you are learning this
This is the daily operating rhythm of a real SOC seat — everything from Modules 1–5 becomes the raw material an analyst processes through this exact set of tools and steps.
Unit contents11
Theory Lessons(10)
Security Operations & the SOC
Theory+40 XPSecurity Telemetry & Data Sources
Theory+40 XPLogs, Parsing & Normalization
Theory+40 XPSIEM Fundamentals
Theory+40 XPDetection Fundamentals
Theory+40 XPAlert Triage
Theory+40 XPIncident Response Lifecycle
Theory+40 XPMITRE ATT&CK & Cyber Kill Chain
Theory+40 XPSecurity Investigation & Reporting
Theory+40 XPModule Review — Analyst Mini-Scenario
Theory+40 XP
Practical Labs(1)
- 07
Modern Security & Career Exploration
Where security extends beyond the SOC — cloud, applications, DevSecOps, Zero Trust and automation — plus a guided tour of the career fields this foundation opens the door to.
BeginnerAvailableWhy you are learning this
Almost every modern organization runs cloud and web applications alongside its traditional network — and every learner eventually needs to choose which of these fields to specialize in.
Unit contents10
Theory Lessons(9)
Modern Security Landscape
Theory+40 XPCloud Security Fundamentals
Theory+40 XPApplication Security Fundamentals
Theory+40 XPContainers, DevSecOps & Infrastructure as Code
Theory+40 XPZero Trust & Modern Identity
Theory+40 XPAutomation for Security
Theory+40 XPGovernance, Risk, Privacy & Resilience
Theory+40 XPExplore Cybersecurity Careers
Theory+40 XPYour Next Step / Foundations Review
Theory+40 XP
Practical Labs(1)