SOC Analyst L1
Learn how modern SOC analysts monitor, investigate, triage and respond to security events — by doing the work, not by memorising definitions.
What you will be able to do
- Decide whether an alert is a true positive, a false positive, or needs escalation — and defend that decision with evidence.
- Reconstruct what happened on a host from Windows event logs and process telemetry.
- Identify suspicious network behaviour such as beaconing, DNS tunnelling and unexpected outbound traffic.
- Write an incident summary another analyst can act on without asking follow-up questions.
Units
- 01
Cybersecurity & SOC Fundamentals
What a SOC actually does, how events become alerts, and how an L1 analyst decides what matters.
BeginnerAvailableWhy you are learning this
Every shift you work begins with a queue of alerts and a finite amount of time. This module is where you learn the judgement that decides which alert you open first — the single most-used skill in the role.
Unit contents9
Theory Lessons(4)
Practical Labs(5)
- 02
Networking Fundamentals
OSI and TCP/IP, ports and protocols, DNS, HTTP and TLS — framed around what an analyst needs to read traffic.
BeginnerAvailableWhy you are learning this
You cannot call traffic suspicious until you know what ordinary traffic looks like.
Unit contents10
Theory Lessons(4)
Practical Labs(6)
Reading the Perimeter Log
Browser Lab+150 XPTwo Hosts, One Problem
Investigation+250 XPSuspicious PowerShell Activity
Investigation+400 XPModule Challenge: Three Signals, One Answer
Challenge+300 XPBlack Box: Suspicious Outbound Communication
Black Box+350 XPJob Simulation (Prototype): One Alert, Start to Handover
Boss LabJob Simulation+250 XP
- 03
Windows Fundamentals
Processes, services, scheduled tasks, the registry, PowerShell and Active Directory from a defender's angle.
BeginnerAvailableWhy you are learning this
Most enterprise endpoints are Windows, so most of what you investigate is Windows behaviour.
Unit contents11
Theory Lessons(6)
Practical Labs(5)
- 04
Windows Event Logs
Event IDs taught through meaning and correlation rather than memorisation.
BeginnerAvailableWhy you are learning this
Event IDs are the raw material of nearly every host investigation you will run.
- 05
SIEM
Ingestion, fields, searching, aggregation, correlation and detection logic using Elastic/Kibana.
BeginnerAvailableWhy you are learning this
The SIEM is where you spend your shift; query fluency is what makes you fast.
Unit contents5
Theory Lessons(4)
Practical Labs(1)
- 06
IOC Analysis
Indicator types, confidence, enrichment and pivoting — including when an indicator means nothing.
BeginnerAvailableWhy you are learning this
Indicators are how you scope an incident beyond the single host that alerted.
Unit contents5
Theory Lessons(4)
Practical Labs(1)
- 07
Network Investigation
PCAP, DNS, HTTP and TLS analysis for beaconing, exfiltration and malware delivery.
BeginnerAvailableWhy you are learning this
Network evidence often survives when an attacker has cleaned the host.
Unit contents5
Theory Lessons(4)
Practical Labs(1)
- 08
Detection Fundamentals
What makes a detection good — fidelity, detection logic, ATT&CK mapping, and tuning without going blind.
Job-ReadyAvailableWhy you are learning this
Detections decide what reaches your queue at all; understanding them tells you how much to trust each alert.
Unit contents5
Theory Lessons(4)
Practical Labs(1)
- 09
Incident Response
The full lifecycle: validate, triage, scope, investigate, contain, eradicate, recover, learn.
Job-ReadyAvailableWhy you are learning this
Knowing what happened is only half the job; deciding what to do is the other half.
Unit contents5
Theory Lessons(4)
Practical Labs(1)
- 10
Integrated SOC
Tying every pillar together: the analyst's loop, correlating across sources, and triaging a full queue by impact.
Job-ReadyAvailableWhy you are learning this
Real incidents do not arrive labelled by skill — this module teaches how the pillars combine into one shift.
Unit contents6
Theory Lessons(4)
Practical Labs(2)