From networking basics to your first alert investigation.
TCP/IP, DNS, common ports and protocols — the vocabulary every alert is written in. Skip this and every tool afterward becomes memorization instead of understanding.
Most security tooling runs on or investigates Linux systems. Command line fluency isn't optional — it's daily work.
Before touching a SIEM, learn to manually read an auth log or firewall log and explain what happened. The SIEM is just a faster way to search — not a replacement for understanding.
Learn to write queries, correlate events, and — critically — practice deciding which alerts deserve attention and which are noise. This judgment only comes from repetition.
Practice writing clear, structured incident reports. This is the skill that actually gets analysts promoted — not just finding the incident, but communicating it clearly.
Complete a full simulated investigation from alert to report. This becomes the concrete example you talk through in interviews.
Every stage above is built into the SOC Analyst Training program's curriculum, labs, and projects.
View Full Curriculum