Skip to content
LIVE · 12 WEEKS · PROJECT-GRADED

SOC Analyst

Detect, triage, and respond to real intrusions inside a live SIEM environment.

Overview

A security operations center does not run on theory. It runs on people who can look at ten thousand events, find the four that matter, and explain why — in writing, under time pressure, to someone more senior than them.

This program builds that specific competence. You work inside a live SIEM fed by real telemetry, investigate intrusions that were modeled on real incidents, and document every one of them to the standard a shift handover actually demands.

What you’ll learn

Six modules. Every one ends in something you built, not something you watched.

01

Security operations foundations

SOC tiers & workflowAlert lifecycleEscalation pathsShift handover

DeliverableA written triage runbook for a recurring alert class.

02

Log analysis & SIEM engineering

Log normalizationQuery authoringCorrelation rulesDashboardsTuning

DeliverableThree custom detections with documented false-positive rates.

03

Threat detection with MITRE ATT&CK

Tactic & technique mappingDetection coverageGap analysisThreat hunting

DeliverableAn ATT&CK coverage matrix for your lab estate.

04

Endpoint & network investigation

EDR telemetryProcess treesPersistence huntingPCAP analysisDNS & proxy logs

DeliverableA full investigation of a simulated endpoint compromise.

05

Phishing & email threat analysis

Header forensicsAttachment detonationURL analysisUser reporting flows

DeliverableA phishing campaign analysis with IOC extraction.

06

Incident response & reporting

Containment decisionsEvidence handlingTimeline reconstructionExecutive summaries

DeliverableAn end-to-end incident report on a multi-stage intrusion.

Tools you'll operate

Set in mono, not borrowed logos — we're telling you what you'll use, not implying a partnership we don't have.

SplunkWazuhElasticSuricataZeekVelociraptorTheHiveMISPSysmon

Career outcomes

Roles this prepares you for

  • SOC Analyst (Tier 1 / Tier 2)
  • Security Monitoring Analyst
  • Detection Engineer (entry)
  • Incident Response Analyst (entry)

What you can do on day one

  • Work a live alert queue without supervision
  • Write and tune SIEM queries against production-scale log volume
  • Map observed activity to ATT&CK and justify the mapping
  • Produce an incident report a manager can forward without editing

What you leave with

  • A portfolio of six documented investigations
  • A public technical writeup on a detection you engineered
  • A GitHub repository of your detection rules and runbooks

Who this is for — and who it isn’t

The right-hand column costs us enrollments on purpose. A wrong placement helps nobody twice.

A good fit if

  • IT support, networking, or system administration professionals moving into security
  • Graduates with networking fundamentals who want an operational, hands-on entry point
  • Security professionals who have certifications but no investigation experience

Probably not if

  • You want an offensive, exploitation-focused role — take Penetration Testing instead
  • You cannot commit to attending live sessions in real time
  • You are looking for exam preparation rather than operational capability

Questions about this track

Book your call

Thirty minutes. One practitioner. A roadmap you keep.

  • We map your current skills, background, and real constraints
  • We identify the specific gaps between you and your target role
  • We recommend a track — or tell you honestly if now isn't the right time
  • You receive a written roadmap by email, whether or not you join
30 minutes
1:1, not a webinar
No payment talk

No sales pressure, and no payment discussion unless you raise it.

Can’t find a slot that works? Email info@skillxgen.com and we’ll sort a time manually.

Step 1 of 3 — Your details

We use your details only to arrange this call. Privacy.