SOC Analyst
Detect, triage, and respond to real intrusions inside a live SIEM environment.
Overview
A security operations center does not run on theory. It runs on people who can look at ten thousand events, find the four that matter, and explain why — in writing, under time pressure, to someone more senior than them.
This program builds that specific competence. You work inside a live SIEM fed by real telemetry, investigate intrusions that were modeled on real incidents, and document every one of them to the standard a shift handover actually demands.
What you’ll learn
Six modules. Every one ends in something you built, not something you watched.
Security operations foundations
DeliverableA written triage runbook for a recurring alert class.
Log analysis & SIEM engineering
DeliverableThree custom detections with documented false-positive rates.
Threat detection with MITRE ATT&CK
DeliverableAn ATT&CK coverage matrix for your lab estate.
Endpoint & network investigation
DeliverableA full investigation of a simulated endpoint compromise.
Phishing & email threat analysis
DeliverableA phishing campaign analysis with IOC extraction.
Incident response & reporting
DeliverableAn end-to-end incident report on a multi-stage intrusion.
Tools you'll operate
Set in mono, not borrowed logos — we're telling you what you'll use, not implying a partnership we don't have.
Career outcomes
Roles this prepares you for
- SOC Analyst (Tier 1 / Tier 2)
- Security Monitoring Analyst
- Detection Engineer (entry)
- Incident Response Analyst (entry)
What you can do on day one
- Work a live alert queue without supervision
- Write and tune SIEM queries against production-scale log volume
- Map observed activity to ATT&CK and justify the mapping
- Produce an incident report a manager can forward without editing
What you leave with
- A portfolio of six documented investigations
- A public technical writeup on a detection you engineered
- A GitHub repository of your detection rules and runbooks
Who this is for — and who it isn’t
The right-hand column costs us enrollments on purpose. A wrong placement helps nobody twice.
A good fit if
- IT support, networking, or system administration professionals moving into security
- Graduates with networking fundamentals who want an operational, hands-on entry point
- Security professionals who have certifications but no investigation experience
Probably not if
- You want an offensive, exploitation-focused role — take Penetration Testing instead
- You cannot commit to attending live sessions in real time
- You are looking for exam preparation rather than operational capability
Questions about this track
Book your call
Thirty minutes. One practitioner. A roadmap you keep.
- We map your current skills, background, and real constraints
- We identify the specific gaps between you and your target role
- We recommend a track — or tell you honestly if now isn't the right time
- You receive a written roadmap by email, whether or not you join
No sales pressure, and no payment discussion unless you raise it.
Can’t find a slot that works? Email info@skillxgen.com and we’ll sort a time manually.
