๐
Beginner10 hours estimated
SOC Analyst Level 1
Get job-ready for your first Security Operations Center role. Learn how to detect, triage, and respond to security incidents using industry-standard tools and frameworks.
๐ 4 topic areas๐ 13 curated resources๐ 10 quiz questions
What you'll cover
The Threat Landscape
Understand the types of attackers, their motivations, and the most common attack vectors targeting organizations today.
SIEM & SOAR
Master the tools that power every SOC: Security Information and Event Management systems and Security Orchestration platforms.
Incident Response
Learn the 6-phase IR lifecycle: preparation, identification, containment, eradication, recovery, and lessons learned.
Log Analysis & Threat Hunting
Learn to read Windows Event Logs, Linux syslogs, and network flow data to find attacker activity.
๐๐๐๐
Windows Event Log IDs Cheat Sheet
Searchable encyclopedia of Windows security event IDs
TryHackMe: SOC Level 1 Path (free tier)
Hands-on labs for SOC fundamentals
SANS Log Management Guide
Best practices for log collection and analysis
Microsoft Defender for Identity Lesson
Detecting identity-based attacks like DCSync and lateral movement in AD
Knowledge Check
Path Summary
- Level
- Beginner
- Estimated time
- 10 hours
- Topics
- 4
- Resources
- 13
- Quiz questions
- 10
- Passing score
- 70% (7/10)