Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Hard Hard90 hours

SOC Analyst L3

Own the investigation, not just the alert. Scope an intrusion end to end, correlate across every source, lead a hunt, validate and tune detections without creating blind spots, and make evidence-supported escalation and closure decisions like a senior analyst. Recommended after SOC Analyst L2.

Recommended first:SOC Analyst L2
Incident TriageLog AnalysisSIEM OperationThreat HuntingDetection EngineeringThreat IntelligenceAnalyst Reporting

What you will be able to do

  • Own an investigation end to end — scope it, hold a standard of proof, and deliver an evidence-supported conclusion.
  • Correlate endpoint, identity and network evidence into one causally-ordered attack timeline.
  • Validate and tune detections — cut false positives without opening a false-negative blind spot.
  • Judge severity and confidence, decide what to escalate, and hand over a record the next analyst can act on.

Units

  1. 01

    Owning the Investigation

    Step up from handling alerts to owning cases: scope the question, hold a standard of proof, weigh evidence quality, and write a conclusion that states what happened and how you know.

    Job-ReadyAvailable

    Why you are learning this

    A senior analyst is handed a case, not a single alert — and is accountable for the verdict. Owning an investigation means deciding what question you are answering, what would prove or disprove it, and when the evidence is strong enough to conclude. Everything later in the path rests on this discipline. (SOC Analyst L2 is the recommended background.)

    Unit contents4
  2. 02

    Correlating the Full Picture

    Read an intrusion across endpoint, identity and network at once: pivot on shared entities, reason about a process tree and an authentication anomaly together, and rebuild one clock-corrected, causally-ordered timeline.

    Job-ReadyAvailable

    Why you are learning this

    The cases that reach a senior analyst never live in one source. Correlating endpoint, identity and network — and telling a causal chain from a coincidence — is how you reconstruct what actually happened and how far it went. This is the raw material every later decision (hunt, tuning, escalation) depends on.

    Unit contents3
  3. 03

    Threat Hunting Leadership

    Lead a hunt, not just run queries: turn a case finding into a falsifiable, prioritised hypothesis, scope it to the right data sources, and judge whether a rare result actually confirms the hypothesis or is just uncommon.

    Job-ReadyAvailable

    Why you are learning this

    Detections only catch what someone already wrote a rule for; a senior analyst extends a confirmed case into a hunt for the rest of the intrusion — and decides which hypothesis is worth the hours. Leading a hunt is choosing the question, the data and the bar for confirmation, then closing the loop into detection.

    Unit contents3
  4. 04

    Detection Validation & Tuning

    Judge whether a detection actually works: read its logic for false positives and false negatives, tune it with suppression, exclusion and thresholds without opening a blind spot, and map coverage against ATT&CK to see the gaps.

    Job-ReadyAvailable

    Why you are learning this

    A rule that fires 400 times a day is ignored, and a rule tuned carelessly stops catching the attack. Validating and tuning detections — cutting noise without cutting the real signal, and knowing suppression from exclusion — is the senior skill that keeps the whole SOC's alerting trustworthy. This is judgment about detections, above authoring them.

    Unit contents3
  5. 05

    Scope, Escalate, Conclude

    Bring the investigation home: measure the blast radius across assets and accounts, express severity and confidence honestly, decide what and when to escalate, and hand over a conclusion the next analyst — or an executive — can act on.

    Job-ReadyAvailable

    Why you are learning this

    The hardest part of a senior analyst's job is not finding evidence — it is deciding what it means, how far it reached, and what to do about it under time pressure. Scoping, an honest severity/confidence call, a defensible escalation decision and a clear handover are what turn an investigation into action. This module ties the path together and sets up the capstone.

    Unit contents4

Recommended next