Career path · SOC analyst
Defensive Security Pathway: networking and Linux to security engineering
Seven courses from reading a packet capture to engineering the detections a security team runs on: networking, Linux administration, SOC investigation, incident response, detection engineering, security engineering, and the attacker's side of web security. Five of the seven include a hosted lab on a real virtual machine.
- Starting level
- No experience needed
- Content time
- 106 h 55 min
- lesson time, from the published courses
- Suggested pace
- About 17 weeks
- planning estimate, at your own pace
- Weekly commitment
- 5–8 hours
- suggested study time
- Courses
- 7
- Lessons
- 70
- Labs
- 5
- on real virtual machines
- Certificate
- On completion
- Ultiblob-issued, verifiable by serial

Before you start
Is this path for you?
Defensive security taught in the order the work actually demands it. You cannot triage an alert on a host you do not understand, so the path starts with networking and Linux and only then reaches the SOC — logs, alerts, and deciding which of them matters. The second half is the harder half: running an incident to its end, writing the detections rather than consuming them, hardening the systems, and seeing how a web application is attacked. 70 lessons, about 107 hours of lesson content, with graded checks throughout.
Who it is for
- Career changers starting with no security background
- IT support and systems staff moving into a security operations team
- Junior SOC analysts who want the engineering half of the role
- Administrators responsible for detection and response at a smaller organisation
What you should know
- Comfortable using a computer and a web browser
- No prior networking, Linux or security experience is assumed
What you will need
- A computer with a current web browser
- A stable internet connection
- Lab machines are hosted by Ultiblob and isolated from every other tenant; nothing is installed on your own computer
Curriculum
5 stages, in the order the work happens
Stage 1
Networking and Linux
Networking and Linux
Stage 2
SOC investigations
SOC investigations
Stage 3
Incident response
Incident response
Stage 4
Detection engineering
Detection engineering
Stage 5
Security engineering
Security engineering
Hands-on
Labs on this path
Each of these courses provisions virtual machines for you on the Ultiblob cluster and opens a console in your browser. The topology below is the published blueprint — roles and operating systems only.
- Networking Foundations
Beginner · 12 h 40 min
- net01· linux
- Linux System Administration
Beginner · 10 h 35 min
- linux01· linux
- SOC Analyst Foundations
Beginner · 15 h 55 min
- soc01· linux
- Incident Response Foundations
Intermediate · 14 h 40 min
- soc01· linux
- Security Engineering Foundations
Advanced · 23 h 20 min
- linux01· linux
Price and enrollment
$249.00
Introductory pricing. Review the current price before checkout.
- labs included
- certificate on completion
Before you decide
What we will not promise
- A job, a salary, or an employer introduction. We teach and we let you practise; we do not place people.
- Accreditation. An Ultiblob certificate records what you completed here. It is not an industry certification.
- Statistics we have not measured. You will not find completion rates, placement rates or student counts on this site until they exist and are audited.
We would rather lose you here than mislead you.
$249.00
introductory price