SOC Analyst Foundation
Learn how a real Security Operations Center runs — from alert to closed investigation.
- Level
- Foundation
- Format
- Live online cohort with recorded sessions
- Modules
- 6 assessed modules
About this program
Most people entering security operations have never seen what an analyst actually does for eight hours a day. They have seen tool demos and exam objectives. This program replaces that with the real shape of the work.
You start with the fundamentals a SOC assumes you already have — how identity, networking, logging and endpoints fit together — then move into the alert queue. From the middle of the program onward, every session is an investigation: something fired, and you determine what happened, whether it matters, and what should be done about it.
You finish having run investigations end to end, escalated cases properly, and written incident documentation that has been reviewed line by line — work that gives an interviewer something concrete to ask you about.
What you will be able to do
- Triage an alert queue and decide what deserves attention first
- Investigate phishing, malware, identity and endpoint alerts end to end
- Read and question log data instead of trusting a tool's verdict
- Write incident notes, escalations and closure summaries a lead will accept
- Explain the MITRE ATT&CK techniques behind what you just investigated
- Present your investigations clearly in a technical interview
Syllabus
6 modules. Every one ends in assessed, written work that a practitioner reviews.
How a real enterprise network, identity estate and endpoint fleet fit together • Where logs come from and why coverage gaps exist • The security team map: SOC, IR, engineering, GRC, and who owns what • Tiered operations, shift models and escalation paths
Windows event logs and endpoint telemetry that matters • Firewall, proxy, DNS and authentication logs • Log normalisation, parsing and why field names ruin queries • MITRE ATT&CK as a working vocabulary, not a poster
Alert triage: severity, context, asset criticality and business hours • Building an investigation timeline from scattered evidence • True positive, false positive, benign positive — and defending your call • Writing analyst notes that survive review
Header analysis, sender infrastructure and authentication failures • Inspecting attachments and payloads safely • Credential harvesting pages and post-compromise indicators • Scoping blast radius: who else received it, who clicked, what followed
Malware behaviour on an endpoint and what the telemetry recorded • Persistence mechanisms and how they surface in logs • Suspicious sign-ins, impossible travel and token misuse • Tracing lateral movement across hosts and accounts
The incident lifecycle: detect, contain, eradicate, recover, review • Containment decisions and their business cost • Running a post-incident review without blame • Presenting an investigation under interview conditions
What you finish with
Portfolio-grade work, reviewed by a practitioner — the part an interviewer can actually ask you about.
- 1A full phishing campaign investigation with scoped impact and recommended actions
- 2An endpoint compromise timeline reconstructed from raw telemetry
- 3A written incident report and executive summary for a simulated breach
- 4A personal detection notebook mapped to MITRE ATT&CK
Is SOC Analyst Foundation the right starting point?
Forty-five minutes with a mentor will settle it. If a different program suits your background better, they will say so.
Prefer email? connectbluelayersacademy@gmail.com
What the call actually is
- 45 minutes, with a mentor rather than a sales team
- A written recommendation you keep either way
- An honest answer if a program is not right for you yet
We do not guarantee placement, and we will say so on the call. What we are accountable for is whether you finish able to do the work.
