SOC Analyst L3
Own the investigation, not just the alert. Scope an intrusion end to end, correlate across every source, lead a hunt, validate and tune detections without creating blind spots, and make evidence-supported escalation and closure decisions like a senior analyst. Recommended after SOC Analyst L2.
What you will be able to do
- Own an investigation end to end — scope it, hold a standard of proof, and deliver an evidence-supported conclusion.
- Correlate endpoint, identity and network evidence into one causally-ordered attack timeline.
- Validate and tune detections — cut false positives without opening a false-negative blind spot.
- Judge severity and confidence, decide what to escalate, and hand over a record the next analyst can act on.
Units
- 01
Owning the Investigation
Step up from handling alerts to owning cases: scope the question, hold a standard of proof, weigh evidence quality, and write a conclusion that states what happened and how you know.
Job-ReadyAvailableWhy you are learning this
A senior analyst is handed a case, not a single alert — and is accountable for the verdict. Owning an investigation means deciding what question you are answering, what would prove or disprove it, and when the evidence is strong enough to conclude. Everything later in the path rests on this discipline. (SOC Analyst L2 is the recommended background.)
- 02
Correlating the Full Picture
Read an intrusion across endpoint, identity and network at once: pivot on shared entities, reason about a process tree and an authentication anomaly together, and rebuild one clock-corrected, causally-ordered timeline.
Job-ReadyAvailableWhy you are learning this
The cases that reach a senior analyst never live in one source. Correlating endpoint, identity and network — and telling a causal chain from a coincidence — is how you reconstruct what actually happened and how far it went. This is the raw material every later decision (hunt, tuning, escalation) depends on.
- 03
Threat Hunting Leadership
Lead a hunt, not just run queries: turn a case finding into a falsifiable, prioritised hypothesis, scope it to the right data sources, and judge whether a rare result actually confirms the hypothesis or is just uncommon.
Job-ReadyAvailableWhy you are learning this
Detections only catch what someone already wrote a rule for; a senior analyst extends a confirmed case into a hunt for the rest of the intrusion — and decides which hypothesis is worth the hours. Leading a hunt is choosing the question, the data and the bar for confirmation, then closing the loop into detection.
- 04
Detection Validation & Tuning
Judge whether a detection actually works: read its logic for false positives and false negatives, tune it with suppression, exclusion and thresholds without opening a blind spot, and map coverage against ATT&CK to see the gaps.
Job-ReadyAvailableWhy you are learning this
A rule that fires 400 times a day is ignored, and a rule tuned carelessly stops catching the attack. Validating and tuning detections — cutting noise without cutting the real signal, and knowing suppression from exclusion — is the senior skill that keeps the whole SOC's alerting trustworthy. This is judgment about detections, above authoring them.
- 05
Scope, Escalate, Conclude
Bring the investigation home: measure the blast radius across assets and accounts, express severity and confidence honestly, decide what and when to escalate, and hand over a conclusion the next analyst — or an executive — can act on.
Job-ReadyAvailableWhy you are learning this
The hardest part of a senior analyst's job is not finding evidence — it is deciding what it means, how far it reached, and what to do about it under time pressure. Scoping, an honest severity/confidence call, a defensible escalation decision and a clear handover are what turn an investigation into action. This module ties the path together and sets up the capstone.
Recommended next
Threat Hunting
Proactive, hypothesis-driven investigation — finding attacker behavior the alerts missed, and turning what you find into new detections. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
Detection Engineering
Turning attacker behavior and telemetry into high-quality, maintainable detections — from requirements and data quality through detection logic, testing, false-positive tuning, coverage and production readiness. Tool-neutral (Sigma-style logic). Recommended prior knowledge: SOC, Threat Hunting or Malware Analysis.
Incident Response
Move from a confirmed alert into structured response: validate, scope, preserve evidence, contain, eradicate, recover — and report to both engineers and executives. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.