SOC Analyst Fundamentals: How to Get Hands-On Experience Before Your First SOC Job

“How do I get experience without the job, and the job without experience?”

That question drove our September 23 Cover6 Community session, SOC Analyst Fundamentals. The short answer: work real data, save your work, and show it. The long answer is below, along with the full replay, the free handout and the lab we used on stream.

YouTube thumbnailYouTube icon

What a SOC analyst actually does

A Security Operations Center watches an organization’s network, endpoints and cloud around the clock. Tier 1 triages the alert queue. Tier 2 investigates what Tier 1 escalates. Tier 3 hunts, tunes detections and handles the incidents nobody else can close. Every tier runs on the same loop: collect telemetry, detect, triage, respond, and feed what you learned back into the detections.

Two ideas carry most of the job.

  • True positive vs. false positive. A true positive is something that really happened. A false positive is a rule that got it wrong. You will see plenty of both, and your disposition note is how your manager knows which one you found and why.
  • Institutional knowledge. Knowing what a server does, who owns it and what normal looks like is what separates a real investigation from a guess. A brute-force tool running against a lab box someone told you about is noise. The same traffic against a production server nobody warned you about is your next shift-change brief.

Quiz: 400 failed logins, then one success

We asked the room: the queue shows 400 failed SSH logins from one IP, then one successful login on a service account. What do you do? Close it, force a password reset, block the IP?

Focus on the one thing that was real: the success. Four hundred failures is not someone fat-fingering a password. Confirm the successful login, scope what that account touched afterward, and then ask the uncomfortable question: why did 400 attempts get through before anything stopped them?

Investigate like it’s your house

An investigation is a timeline, and the analyst’s job is to separate what is known from what is assessed. One IP hits ports 22, 80 and 443 inside three seconds: high confidence that’s a port scan. The same IP then makes 57 failed SSH logins as admin: high confidence of password guessing.

The analogy we use: your system is a mansion. Its services are the staff, and its ports are the doors and windows. Someone knocking at the front door is normal. Someone at the back door gets your attention. Someone peeking into the kids’ bedroom window means you investigate now. A port scan is somebody walking the property checking which windows are unlocked.

Six ways to get hands-on before your first SOC role

Great players have a court at home. That’s why they’re good at their job. Here’s yours:

  1. Work in a live SIEM. SIEM licenses are hard to come by, so we built one you can use. More on that below.
  2. Analyze real traffic. Brad Duncan’s Malware-Traffic-Analysis.net has years of PCAP exercises. PCAP or it didn’t happen: in the job, you should be requesting packet captures on most alerts.
  3. Play CTFs. We run a new Cover6 CTF every month, and organizations submit challenges, so the people who do well get noticed by the people who hire.
  4. Learn an EDR. Endpoint detection tools like ThreatResponder and CrowdStrike are standard in a SOC. For a free option at home, install Wazuh.
  5. Build a home lab. Attack your own machines, then go find yourself in the logs.
  6. Show your work. Getting into cyber is like trying to get run on someone else’s court. Nobody picks you if they’ve never seen you play, and a nice résumé isn’t the same as game film. Write up your labs and publish them.

Read threat reports fast, and write like you study

Analysts live on outside reporting: CISA advisories, the Known Exploited Vulnerabilities catalog, FBI IC3 and The DFIR Report. Read them for three things: what happened, who it targets, and the indicators you can search for in your own environment.

Then write your own reports the way you’d make study notes: in as few words as possible. What happened, what we’re doing about it, what you should do about it, and where to read more. Nobody on the watch floor has time to dig through a long report. Be the analyst leadership calls because they know you’ll have the answer.

Live walk-down: the ShinyHunters FBI claim

On the day of the stream, the group ShinyHunters claimed a breach of an FBI jobs site. We walked it down the way an analyst would, as the story was still developing.

  1. Separate fact from claim. Some of what circulated was confirmed. The bigger numbers and the claimed entry point were still unverified. Your brief says which is which.
  2. Ask whether it applies to you. Do we run the same application? Are we exposed? Are we vulnerable? If we are, what’s at stake? You’re not the FBI, but you might run the same software.
  3. Turn the indicators into saved filters. Build Wireshark display filters and Splunk searches for the reported IPs, domains and net blocks, name them, and save them. Build them once, and next time it’s one click to see whether the same activity is hitting you.
  4. Check outbound traffic first. Outbound traffic is either a response to something or something you started. Think of it this way: your ex calling you isn’t the problem. The log showing you picked up, or called back, is.
  5. End every hunt with a note. The next analyst in your seat needs to know what the filter was for and what you found.
  6. Tell the story. A link chart, in the spirit of Analyst’s Notebook, shows how attacker, infrastructure and victims connect. The leadership brief leads with the bottom line: claimed, not verified; indicators searched, no hits; here’s what we’re watching for next.

Keep the whole SOC updated

At JTF-GNO, Tyrone E. Wilson kept a running brief for the watch floor: what’s happening, what we’re seeing, what other agencies are seeing, emerging threats and awareness tips. The Cover6 Watchroom on our YouTube channel is that brief, made public. If you’re in a SOC, build your own version for your team.

Get your reps in

  • Free handout: the searches, the filters, the report template and a 30-day practice plan. Download the student handout.
  • Cover6 First Watch: seven days, free, in a live Splunk lab with a full intrusion scenario and a target you can attack and then triage yourself. Start First Watch.
  • SOC Analyst Prep: twelve months of lab access and practice exams when you’re ready to go further. See SOC Analyst Prep Labs.
  • Live workshops: two days live with Tyrone E. Wilson, running October, November and December. See workshop dates.

Cover6 Community meets online most Wednesdays at 6:00 PM ET, streamed live on YouTube. Join us on Meetup.

The 6 — Free Newsletter

Job openings, new courses, free workshops, and what’s working in cyber careers right now — straight to your inbox.

Free forever. Confirm by email, unsubscribe any time. We never share your address.

Shopping Cart
Scroll to Top