Course 1
Learning path
SOC Analyst
Build operational skill in monitoring, detection, triage, hunting, and response.
This path groups the courses for one direction. Use it to understand the sequence, then open the specific course you want to work through.
Courses
24
Modules
24
Lessons
153
Completion
0%
Courses in this path
Open the course you want to work through
This path groups related courses into one branch. Course pages stay focused on the lesson-by-lesson workspace.
Course 2
Networking Foundations
Course 3
Threat Landscape and Attacker Thinking
Course 4
Operating Systems for Defenders
Course 5
Cryptography Essentials
Course 6
Defensive Web Fundamentals
Course 7
Identity and Access Management
Course 8
System Hardening Fundamentals
Course 9
Logging, Monitoring, and Telemetry
Course 10
Blue Team Operations
Course 11
Security Governance and Program Foundations
Course 12
Cloud Security Foundations
Course 13
SOC Analyst Fundamentals
Course 14
Detection Engineering
Course 15
Incident Response Operations
Course 16
Threat Hunting Fundamentals
Course 17
Threat Intelligence for SOC Analysts
Course 18
SIEM Query Fundamentals
Course 19
Writing Detections with ATT&CK
Course 20
SOC Analyst Capstone
Course 21
Applied Malware Analysis for Defenders
Course 22
Advanced Threat Hunting
Course 23
Incident Response Leadership
Course 24
Security Operations Program Design
Module preview
What this path covers
Preview the modules and lesson sequence here, then use each course page when you want the full execution view.
Security Foundations
You are currently working through Security Purpose and Defensive Outcomes in this module.
Preview lessons
- Security Purpose and Defensive OutcomesCurrent
- Confidentiality, Integrity, and AvailabilityLocked
- Authentication, Authorization, and AccountabilityLocked
+5 more lessons in this module
Networking Foundations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Network Layers and Why They MatterLocked
- Network Identity: IP Addresses, MAC Addresses, and AttributionLocked
- Ports, Protocols, and ServicesLocked
+5 more lessons in this module
Threat Landscape and Attacker Thinking
Complete the lessons in sequence to move this path forward.
Preview lessons
- Attacker Motivations and ObjectivesLocked
- The Shape of an ATT&CKLocked
- Initial Access PatternsLocked
+3 more lessons in this module
Operating Systems for Defenders
Complete the lessons in sequence to move this path forward.
Preview lessons
- Processes, Users, and the Idea of Security ContextLocked
- Windows Essentials for DefendersLocked
- Linux Essentials for DefendersLocked
+3 more lessons in this module
Cryptography Essentials
Complete the lessons in sequence to move this path forward.
Preview lessons
- Cryptography Purpose and Defender ContextLocked
- Symmetric CryptographyLocked
- Asymmetric CryptographyLocked
+4 more lessons in this module
Defensive Web Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- Web Architecture and Request FlowLocked
- URLs, Domains, DNS, and HostingLocked
- HTTPS and TLS in the BrowserLocked
+5 more lessons in this module
Identity and Access Management
Complete the lessons in sequence to move this path forward.
Preview lessons
- Identity, Accounts, and the Identity LifecycleLocked
- Authentication Factors and Modern AuthenticationLocked
- Federated Identity: SSO, OAuth, and OpenID ConnectLocked
+4 more lessons in this module
System Hardening Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- System Hardening Purpose and Defensive ValueLocked
- Configuration Baselines and BenchmarksLocked
- Patch ManagementLocked
+3 more lessons in this module
Logging, Monitoring, and Telemetry
Complete the lessons in sequence to move this path forward.
Preview lessons
- High-Quality Security TelemetryLocked
- The Major Log Sources Every Defender Should KnowLocked
- SIEM, Log Management, and the Detection PlatformLocked
+3 more lessons in this module
Blue Team Operations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Blue Team Mission and Daily WorkLocked
- The Incident LifecycleLocked
- SOC Structure and Analyst RolesLocked
+3 more lessons in this module
Security Governance and Program Foundations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Security Governance Purpose and Operating ModelLocked
- The Framework and Regulatory LandscapeLocked
- Risk Management: Identification, Assessment, and TreatmentLocked
+3 more lessons in this module
Cloud Security Foundations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Cloud Security Model and Shared ResponsibilityLocked
- The Shared Responsibility ModelLocked
- Cloud Identity and Access ManagementLocked
+3 more lessons in this module
SOC Analyst Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- The SOC Analyst Role in DepthLocked
- A Structured Methodology for Alert TriageLocked
- Investigation Deep Dive: Pivoting Through TelemetryLocked
+4 more lessons in this module
Detection Engineering
Complete the lessons in sequence to move this path forward.
Preview lessons
- Detection Engineering Purpose and WorkflowLocked
- Building Detections from Threat to RuleLocked
- Testing and Validating DetectionsLocked
+4 more lessons in this module
Incident Response Operations
Complete the lessons in sequence to move this path forward.
Preview lessons
- The IR Role in DepthLocked
- Initial Incident Response: The First HourLocked
- Containment Strategy: Short-Term and Long-Term Trade-OffsLocked
+4 more lessons in this module
Threat Hunting Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- Threat Hunting Purpose and PracticeLocked
- Hypothesis-Driven Hunting: A Structured ApproachLocked
- Data-Driven Hunting and Long-Tail SignalsLocked
+4 more lessons in this module
Threat Intelligence for SOC Analysts
Complete the lessons in sequence to move this path forward.
Preview lessons
- Threat Intelligence Purpose and PracticeLocked
- Sources and Evaluating IntelligenceLocked
- Applying Intelligence in OperationsLocked
+3 more lessons in this module
SIEM Query Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- SIEM Data Models and Log NormalizationLocked
- Aggregation and Statistical Analysis for Threat DetectionLocked
- Time-Series Analysis and Multi-Source CorrelationLocked
+2 more lessons in this module
Writing Detections with ATT&CK
Complete the lessons in sequence to move this path forward.
Preview lessons
- ATT&CK as a Detection Coverage FrameworkLocked
- Initial Access and Execution DetectionsLocked
- Persistence and Credential AccessLocked
+2 more lessons in this module
SOC Analyst Capstone
Complete the lessons in sequence to move this path forward.
Preview lessons
- Initial Alert Triage: Monday 9:23 AmLocked
- Investigation Expansion: Monday 10:00 AmLocked
- Containment and Eradication: Monday to WednesdayLocked
+3 more lessons in this module
Applied Malware Analysis for Defenders
Complete the lessons in sequence to move this path forward.
Preview lessons
- Lab Setup and Analysis FundamentalsLocked
- Static AnalysisLocked
- Dynamic AnalysisLocked
+3 more lessons in this module
Advanced Threat Hunting
Complete the lessons in sequence to move this path forward.
Preview lessons
- The Peak Hunting FrameworkLocked
- Hunting Living-Off-The-Land TechniquesLocked
- Cloud Threat HuntingLocked
+3 more lessons in this module
Incident Response Leadership
Complete the lessons in sequence to move this path forward.
Preview lessons
- The Incident Commander RoleLocked
- Multi-Team Coordination During IncidentsLocked
- Communication Under PressureLocked
+3 more lessons in this module
Security Operations Program Design
Complete the lessons in sequence to move this path forward.
Preview lessons
- SOC Operating ModelsLocked
- Staffing and Shift DesignLocked
- Alert Management and SLA DesignLocked
+2 more lessons in this module
