Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Beginner Medium120 hours

SOC Analyst L1

Learn how modern SOC analysts monitor, investigate, triage and respond to security events — by doing the work, not by memorising definitions.

Network AnalysisWindows SecurityLog AnalysisSIEM OperationIOC AnalysisIncident TriageThreat IntelligenceAnalyst Reporting

What you will be able to do

  • Decide whether an alert is a true positive, a false positive, or needs escalation — and defend that decision with evidence.
  • Reconstruct what happened on a host from Windows event logs and process telemetry.
  • Identify suspicious network behaviour such as beaconing, DNS tunnelling and unexpected outbound traffic.
  • Write an incident summary another analyst can act on without asking follow-up questions.

Units

  1. 01

    Cybersecurity & SOC Fundamentals

    What a SOC actually does, how events become alerts, and how an L1 analyst decides what matters.

    BeginnerAvailable

    Why you are learning this

    Every shift you work begins with a queue of alerts and a finite amount of time. This module is where you learn the judgement that decides which alert you open first — the single most-used skill in the role.

    Unit contents9
  2. 02

    Networking Fundamentals

    OSI and TCP/IP, ports and protocols, DNS, HTTP and TLS — framed around what an analyst needs to read traffic.

    BeginnerAvailable

    Why you are learning this

    You cannot call traffic suspicious until you know what ordinary traffic looks like.

    Unit contents10
  3. 03

    Windows Fundamentals

    Processes, services, scheduled tasks, the registry, PowerShell and Active Directory from a defender's angle.

    BeginnerAvailable

    Why you are learning this

    Most enterprise endpoints are Windows, so most of what you investigate is Windows behaviour.

    Unit contents11
  4. 04

    Windows Event Logs

    Event IDs taught through meaning and correlation rather than memorisation.

    BeginnerAvailable

    Why you are learning this

    Event IDs are the raw material of nearly every host investigation you will run.

    Unit contents5
  5. 05

    SIEM

    Ingestion, fields, searching, aggregation, correlation and detection logic using Elastic/Kibana.

    BeginnerAvailable

    Why you are learning this

    The SIEM is where you spend your shift; query fluency is what makes you fast.

    Unit contents5
  6. 06

    IOC Analysis

    Indicator types, confidence, enrichment and pivoting — including when an indicator means nothing.

    BeginnerAvailable

    Why you are learning this

    Indicators are how you scope an incident beyond the single host that alerted.

    Unit contents5
  7. 07

    Network Investigation

    PCAP, DNS, HTTP and TLS analysis for beaconing, exfiltration and malware delivery.

    BeginnerAvailable

    Why you are learning this

    Network evidence often survives when an attacker has cleaned the host.

    Unit contents5
  8. 08

    Detection Fundamentals

    What makes a detection good — fidelity, detection logic, ATT&CK mapping, and tuning without going blind.

    Job-ReadyAvailable

    Why you are learning this

    Detections decide what reaches your queue at all; understanding them tells you how much to trust each alert.

    Unit contents5
  9. 09

    Incident Response

    The full lifecycle: validate, triage, scope, investigate, contain, eradicate, recover, learn.

    Job-ReadyAvailable

    Why you are learning this

    Knowing what happened is only half the job; deciding what to do is the other half.

    Unit contents5
  10. 10

    Integrated SOC

    Tying every pillar together: the analyst's loop, correlating across sources, and triaging a full queue by impact.

    Job-ReadyAvailable

    Why you are learning this

    Real incidents do not arrive labelled by skill — this module teaches how the pillars combine into one shift.

    Unit contents6

Recommended next