SOC Analyst Prep Labs

Wishlist Share

About Course

SOC Analyst Prep Labs is built for one outcome: you, working a real SOC analyst job — or working it better than you do right now.

This isn’t about getting experience “without a job.” This is about being ready for the job itself. Twelve modules, 88 lessons, 12 hands-on labs built around the same live infrastructure SOC teams actually use: a Splunk SIEM pre-loaded with real events, and watching the wire.

You’ll move through the full analyst workflow — log triage, threat hunting, network forensics, detection engineering, escalation, and incident documentation. Every lab is scoped the way a real shift is scoped: here’s what’s happening on the network, go find out why.

Show More

Course Content

Topic 1 — SOC Fundamentals
First day on the job. You are reviewing the alert queue. The team briefs you: three major incidents last semester. They hired you because of them.

  • Lesson 1.1 — 100 SOC Analyst Terms
  • Your Four-Certification Roadmap
  • Lesson 1.2 — What Is a SOC?
  • Lesson 1.3 — The SOC Analyst Role
  • Lesson 1.4 — Alert Triage Fundamentals
  • Lesson 1.5 — You vs. The AI
  • Exercise 1 — Alert Triage Decision Tree
  • Lab 1 — Alert Triage in Splunk

Topic 2 — Threat Intelligence and The Landscape
You pull threat intel on groups that targeted universities last year. Two campaigns match TTPs you are seeing in your own logs.

Topic 3 — SIEM Architecture and Splunk Foundations
The Splunk instance was set up six months ago. Nobody has built proper dashboards yet. That is your first project.

Topic 4 — Log Analysis
You find evidence of a brute force campaign that hit the admin network two weeks ago. The previous analyst missed it. You are reconstructing the timeline.

Topic 5 — Network Traffic Analysis
The research network is showing unusual outbound traffic. Dr. Osei's team says nothing has changed. You pull the PCAP.

Topic 6 — Phishing and Email Analysis

Topic 7 — Incident Detection
Three alerts fire in the same 20-minute window. You have to triage all three, determine what is real, and brief Dana before the noon meeting.

Topic 8 — Incident Response
One of those three alerts was real. You are writing the IR report. Marcus wants a brief for the Board by Friday.

Topic 9 — Endpoint Detection and Response
A workstation in the Health Center is behaving strangely. Possible malware. Student health records are at risk. The clock is running.

Topic 10 — Vulnerability Management
You run the first formal vulnerability scan of the public web server. What you find is worse than expected.

Topic 11 — Security Frameworks and Compliance
Dana asks you to map the current security posture to NIST CSF. The gaps you find will drive next year's budget request.

Topic 12 — Threat Hunting

Student Ratings & Reviews

No Review Yet
No Review Yet
Shopping Cart
Scroll to Top