Security Operations · Beginner
SOC Analyst Foundations
Work a synthetic security incident end to end: triage the alert, read the logs, build a timeline, test a detection, preserve the evidence and write a report that does not overclaim.
About this course
A security operations centre runs on a simple loop: something raises a signal, an analyst decides what it means, and someone downstream acts on that decision. This course teaches the loop with your hands on the data rather than on a dashboard. You work on `soc01`, an Ubuntu 24.04 lab machine that carries `auditd`, `fail2ban` and `nginx`, plus a generator that produces a **synthetic** event bundle: SSH authentication logs containing a brute force and one successful login, nginx access logs full of web probing, a process and network snapshot, and a small JSON telemetry file shaped like endpoint-detection output. Everything you investigate is generated inside your own lab from documentation-range addresses. No production log, no customer data and no live target is ever involved. Across ten lessons you learn what each log source can and cannot prove; how to turn an alert into a bounded hypothesis; the `grep`, `awk`, `sort`, `uniq` and `jq` patterns that make a pile of lines answer a question; how brute force, password spraying, web attacks and beaconing actually look in text; how to examine processes, persistence and connections on a suspect host; how to write an `auditd` rule and a `fail2ban` jail and then test them against events you control; what to collect, hash and preserve before you change anything; and how to write an incident report whose confidence language matches its evidence. The final project hands you a fresh incident bundle and asks for a timeline, an indicator list and a report, graded against a rubric and automated lab checks. Windows telemetry is taught from the documented event IDs (4624, 4625, 4688, 7045) using synthetic JSON samples, because the lab machine is Linux.
- Content time
- 15 h 55 min
- Lessons
- 10
- Lab
- Yes
- provisioned for you
- Certificate
- Yes
- on completion
Lesson 1 is free. Enroll in a career path to access its full courses.
Lesson 1 is a free preview — read it without an account.

Outline
Lessons
Lesson 1: The SOC, the analyst and the workflowFree preview
What a security operations centre actually does all day, how work moves from alert to closure, and what "good" looks like in a queue you did not choose.
1 h 15 minLesson 2: Log sources and telemetry
What Linux authentication logs, the journal, auditd, web server logs, firewall and DNS records and Windows Security events each prove — and, more importantly, what they do not.
1 h 30 minLesson 3: Authorize and classify — from alert to hypothesis
Turn one synthetic alert into a bounded case: confirm your authority and scope, set severity and confidence separately, write competing hypotheses, and decide what evidence you need first.
1 h 30 minLesson 4: Working the data — pipelines, timelines and time zones
The grep, awk, sort, uniq and jq patterns that turn a pile of log lines into an answer, and the time-zone work needed to put three disagreeing sources on one timeline.
1 h 50 minLesson 5: Recognising common attack patterns in logs
What brute force, password spraying, web attack probing and beaconing actually look like in raw text, how to tell them apart, and how to reference them with ATT&CK technique ids.
1 h 50 minLesson 6: Investigating a suspicious host
Work through processes, persistence, network connections and accounts on soc01 using the collected artifacts, and find the quiet changes an attacker leaves behind.
1 h 50 minLesson 7: Detection basics — auditd rules, fail2ban jails and testing a rule
Write an auditd rule set and a fail2ban jail, understand what a portable detection rule is, then test your detection against events you control and measure its false positives.
2 hLesson 8: Containment, evidence handling and preservation
Collect in order of volatility, hash everything, keep a custody record, and choose a containment action that fits your authority without destroying the evidence you still need.
1 h 30 minLesson 9: Reporting without overclaiming
Structure an incident report, build an indicator list, and use confidence language that matches your evidence so the reader can act without being misled.
1 h 30 minLesson 10: Continuous improvement — tuning, metrics, playbooks and the handover
Feed the case back into the detections, measure the timings honestly, write the playbook page the next analyst needs, and hand the case over at the boundary where incident response begins.
1 h 10 min
Hands-on
Your lab
Real virtual machines on the Ultiblob cluster, reached from your browser. You administer them; we provision and destroy them.
- vm-01soc01linux
Provisioned for you when you launch the lab from the course. The machines are yours for the access window; release them and launch again whenever you like.
Where it leads