Course

SOC Analyst

A 12-week, hands-on course that trains you for the daily work of a Security Operations Centre analyst, built entirely on Wazuh — the open-source SIEM used in real SOCs. You deploy the full stack, enrol Linux and Windows agents with Sysmon, and then live inside it: writing decoders and rules, mapping detections to MITRE ATT&CK, hunting brute force, privilege escalation and persistence, triaging alerts from raw event to written incident, and running active response and a live incident-response simulation. You finish as a working analyst — able to build detections, investigate an intrusion end to end, cut false positives, and write the report that a manager acts on. Assumes the Cybersecurity for Beginners course or equivalent: comfort with Linux and Windows command lines, networking, logs, and the basics of attacks. You need a laptop with 16 GB of RAM to run the lab. Expect 12–15 hours per week of lessons, labs and a weekly detection or investigation project.

Module 1 — Week 1 — Inside a SOC: Tiers, Shifts & the Alert Lifecycle

  1. ✓What a SOC actually is
    30mFree preview
  2. ✓Tiers, roles and where you start
    25mFree preview
  3. ✓The alert lifecycle: the loop that is the job
    25mFree preview
  4. ✓The metrics a SOC lives by
    25mFree preview
  5. ✓Lab: stand up your analyst workstation
    60mPracticalFree preview
  6. ✓Lab: triage your first alerts
    75mPracticalFree preview
  7. ✓Weekly project: analyse a SOC and your place in it
    150mProjectFree preview

Module 2 — Week 2 — Deploying Wazuh: Architecture & the Single-Node Stack

  1. ✓The Wazuh architecture, properly
    30m🔒
  2. ✓Inside the manager: the analysis pipeline
    30m🔒
  3. ✓The indexer: storage, indices and search
    25m🔒
  4. ✓Operating the stack: health, logs and config
    25m🔒
  5. ✓Lab: deploy and dissect the stack
    75mPractical🔒
  6. ✓Lab: break it and fix it
    75mPractical🔒
  7. ✓Weekly project: an operations runbook
    150mProject🔒

Module 3 — Week 3 — Agents & Log Collection: Linux, Windows & Sysmon

  1. ✓Agent configuration: what actually gets collected
    30m🔒
  2. ✓Windows logging for detection
    30m🔒
  3. ✓Sysmon: the telemetry that makes Windows detectable
    25m🔒
  4. ✓Coverage against volume: choosing what to collect
    25m🔒
  5. ✓Lab: deploy Sysmon and ship it to Wazuh
    75mPractical🔒
  6. ✓Lab: audit your collection coverage
    60mPractical🔒
  7. ✓Weekly project: a log collection strategy
    150mProject🔒

Module 4 — Week 4 — Log Analysis: Decoders & Parsing

  1. ✓Why decoding decides everything downstream
    30m🔒
  2. ✓Regular expressions, practically
    30m🔒
  3. ✓Writing a decoder
    25m🔒
  4. ✓When decoders go wrong
    25m🔒
  5. ✓Lab: write decoders for a custom source
    75mPractical🔒
  6. ✓Lab: debug broken decoders
    60mPractical🔒
  7. ✓Weekly project: a documented decoder pack
    150mProject🔒

Module 5 — Week 5 — Wazuh Rules: Anatomy, Custom Rules & Tuning

  1. ✓Rule anatomy and how matching works
    30m🔒
  2. ✓Levels: the decision that makes or breaks a SOC
    25m🔒
  3. ✓Correlation: detecting patterns, not events
    25m🔒
  4. ✓Tuning: the craft that keeps a SOC usable
    25m🔒
  5. ✓Lab: build a rule pack for real attacks
    75mPractical🔒
  6. ✓Lab: tune a noisy detection without losing it
    60mPractical🔒
  7. ✓Weekly project: a tuned detection rule pack
    150mProject🔒

Module 6 — Week 6 — Mapping Detections to MITRE ATT&CK

  1. ✓ATT&CK: a shared language for attacker behaviour
    30m🔒
  2. ✓The Pyramid of Pain: why some detections are worth more
    25m🔒
  3. ✓Mapping detections and finding your gaps
    25m🔒
  4. ✓Threat-informed defence: prioritising by who targets you
    25m🔒
  5. ✓Lab: map your detections and find the gaps
    75mPractical🔒
  6. ✓Lab: build a technique-level detection
    60mPractical🔒
  7. ✓Weekly project: an ATT&CK coverage assessment
    150mProject🔒

Module 7 — Week 7 — Detecting Common Attacks: Brute Force, Priv-Esc, Persistence

  1. ✓Detecting credential attacks
    30m🔒
  2. ✓Detecting privilege escalation
    30m🔒
  3. ✓Detecting persistence across its many homes
    25m🔒
  4. ✓Detecting lateral movement
    25m🔒
  5. ✓Lab: detect a multi-stage attack
    75mPractical🔒
  6. ✓Lab: build the mid-chain detection pack
    60mPractical🔒
  7. ✓Weekly project: a mid-chain detection suite
    150mProject🔒

Module 8 — Week 8 — FIM, Rootcheck, SCA & Vulnerability Detection

  1. ✓File integrity monitoring at analyst depth
    30m🔒
  2. ✓Rootcheck and configuration assessment
    30m🔒
  3. ✓Vulnerability detection as a SOC input
    25m🔒
  4. ✓Using the capabilities together
    25m🔒
  5. ✓Lab: configure and tune the endpoint capabilities
    75mPractical🔒
  6. ✓Lab: scope a compromise across all four capabilities
    60mPractical🔒
  7. ✓Weekly project: an endpoint detection and scoping capability
    150mProject🔒

Module 9 — Week 9 — Triage & Investigation: From Alert to Incident

  1. ✓Triage: the decision that routes everything
    30m🔒
  2. ✓Investigation: structured reasoning
    30m🔒
  3. ✓The timeline: the investigator's core artefact
    25m🔒
  4. ✓Pivoting and scoping: from one alert to the whole
    25m🔒
  5. ✓Lab: triage a queue under pressure
    60mPractical🔒
  6. ✓Lab: a full investigation, alert to report
    60mPractical🔒
  7. ✓Weekly project: a complete investigation
    150mProject🔒

Module 10 — Week 10 — Incident Response & Active Response Automation

  1. ✓The incident response lifecycle
    30m🔒
  2. ✓Containment, eradication and recovery
    30m🔒
  3. ✓Active response: automating action safely
    25m🔒
  4. ✓SOAR and where automation is going
    25m🔒
  5. ✓Lab: configure safe automated response
    60mPractical🔒
  6. ✓Lab: run a full incident response
    60mPractical🔒
  7. ✓Weekly project: an incident response playbook
    150mProject🔒

Module 11 — Week 11 — Threat Intel, Enrichment, Reporting & SOC Metrics

  1. ✓Threat intelligence: knowing your adversary
    30m🔒
  2. ✓Enrichment: from indicator to decision
    30m🔒
  3. ✓Writing: the skill that makes analysis matter
    25m🔒
  4. ✓Measuring a SOC honestly
    25m🔒
  5. ✓Lab: integrate threat intel and enrichment
    60mPractical🔒
  6. ✓Lab: produce the SOC's written products
    60mPractical🔒
  7. ✓Weekly project: intelligence-driven reporting
    150mProject🔒

Module 12 — Week 12 — Capstone: Detection Engineering & a Live IR Simulation

  1. ✓Bringing the SOC skills together
    30m🔒
  2. ✓The capstone brief
    30m🔒
  3. ✓Planning the capstone
    25m🔒
  4. ✓Where you go from here
    25m🔒
  5. ✓Lab: build the capstone detection capability
    75mPractical🔒
  6. ✓Lab: the live incident response
    75mPractical🔒
  7. ✓Capstone: present, defend, and launch
    165mProject🔒

Already enrolled? Sign in with your enrollment email to unlock all lessons.