Cover6: First Watch — Your First Shift as a SOC Analyst
About Course
In 2020, I gave a demo at BSides NoVA. About 50 people in that room. My main server went down. Then my backup went down. The room laughed it off — they trusted me. But it bothered me. I vowed to get it working properly.
This is that. Free, and yours for 7 days.
— Tyrone E. Wilson, CEO, Cover6 Solutions
It’s Friday at 4:47 PM. You get a call. The registrar can’t reach student records, and someone has left a note on the university website. You’re the SOC analyst on duty at Odapeeka State University.
First Watch is a free, guided SOC investigation in a controlled Cover6 training environment. You’ll use Splunk, packet captures and structured analyst questions to turn observations into conclusions you can defend.
Odapeeka State University is a fictional training scenario. The course combines designed scenario data with PCAP evidence. Your job is to work out what the evidence supports, what it only suggests, and what remains unknown — not to treat every log line as proof of a full incident story.
You’ll practise
- Finding and interpreting reconnaissance, web, authentication and host evidence
- Writing and reading SPL in your own Splunk lab
- Corroborating an observation with the right log source or packet capture
- Recording confidence, uncertainty and the next investigative step
- Connecting findings to practical containment and improvement decisions
How it’s structured
- The Odapeeka investigation: seven lessons, one per stage of the scenario, a knowledge check, and a graded capstone.
- INC-002: incident handling with the PICERL framework, plus a Red Team Drill against a designated Cover6 lab target.
- Operation Alpha (sponsor module): an investigation built for CyberjutsuCon 2026 attendees. It’s open to them and shown to everyone as an example of what an organization or event can add. It isn’t needed to finish the course. Want a module for your team or event? Contact Cover6.
Work at your own pace: every lesson is open from the start.
Completion and certificate
Complete every lesson, pass the capstone (80%, with every rubric row scored) and pass the final knowledge check (70%, unlimited attempts) to earn the First Watch certificate: SOC Analyst, Level I, with 5.5 CPE hours. Anyone can check it at cover6solutions.com/verify. CPE hours may be submitted to your certifying body according to its rules; each body decides what it accepts.
First Watch is aligned with DoD 8140 work role 511, Cyber Defense Analyst.
Lab access
Your Splunk lab credentials are emailed when you enroll, and lab access runs for 7 days from enrollment. Need more time? A 30-Day Lab Extension keeps your lab open.
Scope: use only the Cover6 systems, accounts, PCAPs and links supplied for this course. Don’t scan, probe, log in to or interact with systems outside the stated course environment. An internet-reachable host, a private address or a tool shown in a lesson is never permission to test another system.
If a result doesn’t match the lesson, stop and note the lesson, query, time range and what you got, then ask in the course community. Don’t switch to a different target, data source or broader search.
Where it leads
Next on the track: SOC Analyst Prep Labs, the SOC Analyst Level II course, with 12 months of live Splunk lab access. Want the offensive side? Cover6: First Shell is free.
📥 Course files
📁 Odapeeka PCAP files (Google Drive)
🖥️ Lab
📊 Splunk (sign in with the credentials from your enrollment email)
Course Content
Cover6: First Watch — The Odapeeka State Investigation
-
Welcome to Cover6: First Watch
-
Reference — 100 SOC Analyst Terms to Know
-
Day 1 — Reconnaissance
-
Day 2 — Web Enumeration
-
Day 3 — Initial Access
-
Day 4 — Command & Control
-
Day 5 — Internal Reconnaissance
-
Day 6 — Exfiltration
-
Day 7 — Ransomware
-
Odapeeka Investigation — Knowledge Check
-
Capstone — Odapeeka Incident Findings
-
Capstone — Odapeeka Incident Findings (Graded)