Security Operations Foundations
Break into the SOC. Learn what a Security Operations Center defends, how to read security logs, and how to triage, escalate and hand over alerts like a working analyst, with no prior experience needed.
Tuition
$349
Beginner
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- Explain what a SOC does, how its tiers work, and where a Tier 1 analyst fits in
- Describe the analyst's daily role, shift rhythm, and core responsibilities
- Identify the main security log sources: endpoint, network, identity, and cloud
- Read common log events and formats (Syslog, Windows Event IDs, JSON) and spot what looks abnormal
- Explain how a SIEM ingests, normalizes, and correlates logs into alerts
- Triage an alert into true positive, false positive, or benign, and enrich it with context
- Map suspicious activity to MITRE ATT&CK and assign an appropriate severity
- Escalate a real incident and write clear case notes and a shift-handover the next analyst can act on
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Inside the SOC: the Analyst's World
Meet the Security Operations Center: what it defends, why it runs around the clock, how its tiers divide the work from Tier 1 triage to Tier 3 threat hunting, the in-house versus MSSP and MDR models, and what a real analyst's shift looks like from handover to the tools on the desk.
2 lessons · 5 quiz questions
- 02
Security Telemetry and Log Sources
Every detection begins with data. This module tours the four telemetry pillars a SOC lives on, endpoint (EDR), network, identity, and cloud or application logs, then teaches you to actually read that data: the anatomy of an event, the primacy of UTC timestamps, the three formats you will meet daily (Syslog, Windows Event IDs, and JSON), and how to baseline normal so that abnormal stands out.
2 lessons · 5 quiz questions · assignment
- 03
The SIEM and Alert Triage
Explains how a SIEM ingests, normalizes, and correlates telemetry into alerts through detection rules. Then builds the core Tier 1 skill: triaging an alert into true positive, false positive, or benign using enrichment, severity, and MITRE ATT&CK.
2 lessons · 5 quiz questions
- 04
Monitoring, Escalation and Shift Handover
A SOC runs around the clock, and every shift is a disciplined loop: work the alert queue, triage by severity, escalate real threats into the NIST SP 800-61 incident-response lifecycle, and hand the watch over so cleanly the next analyst misses nothing. This module teaches that loop end to end: playbooks and escalation, case notes, ticketing and SOAR, and the metrics (MTTD, MTTR, dwell time) that prove the team is winning.
2 lessons · 5 quiz questions · assignment