5.00
(3 Ratings)

Cover6: First Watch — Your First Shift as a SOC Analyst

Wishlist Share

About Course

In 2020, I gave a demo at BSides NoVA. About 50 people in that room. My main server went down. Then my backup went down. The room laughed it off — they trusted me. But it bothered me. I vowed to get it working properly.

This is that. Free, and yours for 7 days.

— Tyrone E. Wilson, CEO, Cover6 Solutions


It’s Friday at 4:47 PM. You get a call. The registrar can’t reach student records, and someone has left a note on the university website. You’re the SOC analyst on duty at Odapeeka State University.

First Watch is a free, guided SOC investigation in a controlled Cover6 training environment. You’ll use Splunk, packet captures and structured analyst questions to turn observations into conclusions you can defend.

Odapeeka State University is a fictional training scenario. The course combines designed scenario data with PCAP evidence. Your job is to work out what the evidence supports, what it only suggests, and what remains unknown — not to treat every log line as proof of a full incident story.

You’ll practise

  • Finding and interpreting reconnaissance, web, authentication and host evidence
  • Writing and reading SPL in your own Splunk lab
  • Corroborating an observation with the right log source or packet capture
  • Recording confidence, uncertainty and the next investigative step
  • Connecting findings to practical containment and improvement decisions

How it’s structured

  • The Odapeeka investigation: seven lessons, one per stage of the scenario, a knowledge check, and a graded capstone.
  • INC-002: incident handling with the PICERL framework, plus a Red Team Drill against a designated Cover6 lab target.
  • Operation Alpha (sponsor module): an investigation built for CyberjutsuCon 2026 attendees. It’s open to them and shown to everyone as an example of what an organization or event can add. It isn’t needed to finish the course. Want a module for your team or event? Contact Cover6.

Work at your own pace: every lesson is open from the start.

Completion and certificate

Complete every lesson, pass the capstone (80%, with every rubric row scored) and pass the final knowledge check (70%, unlimited attempts) to earn the First Watch certificate: SOC Analyst, Level I, with 5.5 CPE hours. Anyone can check it at cover6solutions.com/verify. CPE hours may be submitted to your certifying body according to its rules; each body decides what it accepts.

First Watch is aligned with DoD 8140 work role 511, Cyber Defense Analyst.

Lab access

Your Splunk lab credentials are emailed when you enroll, and lab access runs for 7 days from enrollment. Need more time? A 30-Day Lab Extension keeps your lab open.

Scope: use only the Cover6 systems, accounts, PCAPs and links supplied for this course. Don’t scan, probe, log in to or interact with systems outside the stated course environment. An internet-reachable host, a private address or a tool shown in a lesson is never permission to test another system.

If a result doesn’t match the lesson, stop and note the lesson, query, time range and what you got, then ask in the course community. Don’t switch to a different target, data source or broader search.

Where it leads

Next on the track: SOC Analyst Prep Labs, the SOC Analyst Level II course, with 12 months of live Splunk lab access. Want the offensive side? Cover6: First Shell is free.


📥 Course files
📁 Odapeeka PCAP files (Google Drive)

🖥️ Lab
📊 Splunk (sign in with the credentials from your enrollment email)

Show More

Course Content

Cover6: First Watch — The Odapeeka State Investigation

  • Welcome to Cover6: First Watch
  • Reference — 100 SOC Analyst Terms to Know
  • Day 1 — Reconnaissance
  • Day 2 — Web Enumeration
  • Day 3 — Initial Access
  • Day 4 — Command & Control
  • Day 5 — Internal Reconnaissance
  • Day 6 — Exfiltration
  • Day 7 — Ransomware
  • Odapeeka Investigation — Knowledge Check
  • Capstone — Odapeeka Incident Findings
  • Capstone — Odapeeka Incident Findings (Graded)

INC-002 — Incident Response & Red Team Drill

Operation Alpha — CyberjutsuCon 2026 Sponsor Module
<p>A guided incident-response scenario built for CyberjutsuCon 2026. Investigate a designed attack chain in Splunk.</p> <div class="woocommerce"> <div class="woocommerce-info wc-memberships-restriction-message wc-memberships-message wc-memberships-content-restricted-message"> This content is only available to members. </div> </div>

Student Ratings & Reviews

5.0
Total 3 Ratings
5
3 Ratings
4
0 Rating
3
0 Rating
2
0 Rating
1
0 Rating
Great
KJ
3 months ago
This really gives you exposure to the intricacies of incident monitoring and risk management. Coupled with the guided sessions that are currently being provided, it is a great opportunity to gain real world skills.
T
3 months ago
this course really helped me understand the process on attacking and defending a company and it shows both sides of the situation perfectly
Shopping Cart
Scroll to Top