Course
SOC Analyst
A 12-week, hands-on course that trains you for the daily work of a Security Operations Centre analyst, built entirely on Wazuh — the open-source SIEM used in real SOCs. You deploy the full stack, enrol Linux and Windows agents with Sysmon, and then live inside it: writing decoders and rules, mapping detections to MITRE ATT&CK, hunting brute force, privilege escalation and persistence, triaging alerts from raw event to written incident, and running active response and a live incident-response simulation. You finish as a working analyst — able to build detections, investigate an intrusion end to end, cut false positives, and write the report that a manager acts on. Assumes the Cybersecurity for Beginners course or equivalent: comfort with Linux and Windows command lines, networking, logs, and the basics of attacks. You need a laptop with 16 GB of RAM to run the lab. Expect 12–15 hours per week of lessons, labs and a weekly detection or investigation project.
Module 1 — Week 1 — Inside a SOC: Tiers, Shifts & the Alert Lifecycle
- ✓What a SOC actually is30mFree preview
- ✓Tiers, roles and where you start25mFree preview
- ✓The alert lifecycle: the loop that is the job25mFree preview
- ✓The metrics a SOC lives by25mFree preview
- ✓Lab: stand up your analyst workstation60mPracticalFree preview
- ✓Lab: triage your first alerts75mPracticalFree preview
- ✓Weekly project: analyse a SOC and your place in it150mProjectFree preview
Module 2 — Week 2 — Deploying Wazuh: Architecture & the Single-Node Stack
- ✓The Wazuh architecture, properly30m🔒
- ✓Inside the manager: the analysis pipeline30m🔒
- ✓The indexer: storage, indices and search25m🔒
- ✓Operating the stack: health, logs and config25m🔒
- ✓Lab: deploy and dissect the stack75mPractical🔒
- ✓Lab: break it and fix it75mPractical🔒
- ✓Weekly project: an operations runbook150mProject🔒
Module 3 — Week 3 — Agents & Log Collection: Linux, Windows & Sysmon
- ✓Agent configuration: what actually gets collected30m🔒
- ✓Windows logging for detection30m🔒
- ✓Sysmon: the telemetry that makes Windows detectable25m🔒
- ✓Coverage against volume: choosing what to collect25m🔒
- ✓Lab: deploy Sysmon and ship it to Wazuh75mPractical🔒
- ✓Lab: audit your collection coverage60mPractical🔒
- ✓Weekly project: a log collection strategy150mProject🔒
Module 4 — Week 4 — Log Analysis: Decoders & Parsing
- ✓Why decoding decides everything downstream30m🔒
- ✓Regular expressions, practically30m🔒
- ✓Writing a decoder25m🔒
- ✓When decoders go wrong25m🔒
- ✓Lab: write decoders for a custom source75mPractical🔒
- ✓Lab: debug broken decoders60mPractical🔒
- ✓Weekly project: a documented decoder pack150mProject🔒
Module 5 — Week 5 — Wazuh Rules: Anatomy, Custom Rules & Tuning
- ✓Rule anatomy and how matching works30m🔒
- ✓Levels: the decision that makes or breaks a SOC25m🔒
- ✓Correlation: detecting patterns, not events25m🔒
- ✓Tuning: the craft that keeps a SOC usable25m🔒
- ✓Lab: build a rule pack for real attacks75mPractical🔒
- ✓Lab: tune a noisy detection without losing it60mPractical🔒
- ✓Weekly project: a tuned detection rule pack150mProject🔒
Module 6 — Week 6 — Mapping Detections to MITRE ATT&CK
- ✓ATT&CK: a shared language for attacker behaviour30m🔒
- ✓The Pyramid of Pain: why some detections are worth more25m🔒
- ✓Mapping detections and finding your gaps25m🔒
- ✓Threat-informed defence: prioritising by who targets you25m🔒
- ✓Lab: map your detections and find the gaps75mPractical🔒
- ✓Lab: build a technique-level detection60mPractical🔒
- ✓Weekly project: an ATT&CK coverage assessment150mProject🔒
Module 7 — Week 7 — Detecting Common Attacks: Brute Force, Priv-Esc, Persistence
- ✓Detecting credential attacks30m🔒
- ✓Detecting privilege escalation30m🔒
- ✓Detecting persistence across its many homes25m🔒
- ✓Detecting lateral movement25m🔒
- ✓Lab: detect a multi-stage attack75mPractical🔒
- ✓Lab: build the mid-chain detection pack60mPractical🔒
- ✓Weekly project: a mid-chain detection suite150mProject🔒
Module 8 — Week 8 — FIM, Rootcheck, SCA & Vulnerability Detection
- ✓File integrity monitoring at analyst depth30m🔒
- ✓Rootcheck and configuration assessment30m🔒
- ✓Vulnerability detection as a SOC input25m🔒
- ✓Using the capabilities together25m🔒
- ✓Lab: configure and tune the endpoint capabilities75mPractical🔒
- ✓Lab: scope a compromise across all four capabilities60mPractical🔒
- ✓Weekly project: an endpoint detection and scoping capability150mProject🔒
Module 9 — Week 9 — Triage & Investigation: From Alert to Incident
- ✓Triage: the decision that routes everything30m🔒
- ✓Investigation: structured reasoning30m🔒
- ✓The timeline: the investigator's core artefact25m🔒
- ✓Pivoting and scoping: from one alert to the whole25m🔒
- ✓Lab: triage a queue under pressure60mPractical🔒
- ✓Lab: a full investigation, alert to report60mPractical🔒
- ✓Weekly project: a complete investigation150mProject🔒
Module 10 — Week 10 — Incident Response & Active Response Automation
- ✓The incident response lifecycle30m🔒
- ✓Containment, eradication and recovery30m🔒
- ✓Active response: automating action safely25m🔒
- ✓SOAR and where automation is going25m🔒
- ✓Lab: configure safe automated response60mPractical🔒
- ✓Lab: run a full incident response60mPractical🔒
- ✓Weekly project: an incident response playbook150mProject🔒
Module 11 — Week 11 — Threat Intel, Enrichment, Reporting & SOC Metrics
- ✓Threat intelligence: knowing your adversary30m🔒
- ✓Enrichment: from indicator to decision30m🔒
- ✓Writing: the skill that makes analysis matter25m🔒
- ✓Measuring a SOC honestly25m🔒
- ✓Lab: integrate threat intel and enrichment60mPractical🔒
- ✓Lab: produce the SOC's written products60mPractical🔒
- ✓Weekly project: intelligence-driven reporting150mProject🔒
Module 12 — Week 12 — Capstone: Detection Engineering & a Live IR Simulation
- ✓Bringing the SOC skills together30m🔒
- ✓The capstone brief30m🔒
- ✓Planning the capstone25m🔒
- ✓Where you go from here25m🔒
- ✓Lab: build the capstone detection capability75mPractical🔒
- ✓Lab: the live incident response75mPractical🔒
- ✓Capstone: present, defend, and launch165mProject🔒
Already enrolled? Sign in with your enrollment email to unlock all lessons.