SOC & Blue Team
Practice defensive security operations: triage alerts, read SIEM evidence, map threat intelligence, operate incidents, preserve evidence, and hunt for suspicious behavior.
Start with the path, then open the rooms.
Work through the lessons in order. Each lesson starts with the concept, explains the vocabulary, then moves into examples, review checks, browser practice, and saved proof when it is useful.
Outcomes
SOC operations and incident handling
This course is organized around a role path, industry alignment, and proof a learner can keep.
- Separate signal, context, severity, uncertainty, and next action.
- Use SIEM evidence and threat intelligence to decide close, monitor, or escalate.
- Preserve incident and forensic evidence before recovery work.
- Turn hunt hypotheses into repeatable detection improvements.
- Triage notes with summary, severity, evidence, uncertainty, and next action.
- SIEM, threat-intel, containment, forensic, and hunting plans with named owners or decisions.
- Saved Check Work for defensive analyst reasoning.
SOC rooms should require evidence-backed defensive action, preservation boundaries, and a severity-backed next step before completion.
Proof Loop
Examples support the reading, but they are not completion evidence by themselves.
Check Work must pass inside the sandbox before protected rooms can complete.
Learners keep proof by writing expected result, actual result, and next improvement in their own words.
Lessons, checks, explanations, and completion
This map shows what the learner needs to do in each room: learn the concept, pass Check Work when required, explain the result, and keep completion proof.
SOC Fundamentals and the Analyst Role
Check locked2-3 hours
SIEM Fundamentals and Log Analysis
Check locked3-4 hours
Threat Intelligence and MITRE ATT&CK
Check locked3-4 hours
Incident Response from Detection to Containment
Check locked3-4 hours
Digital Forensics and Malware Analysis
Check locked3-4 hours
Threat Hunting and Advanced Detection
Check locked3-4 hours
Useful resources for this course
Curated picks that support this learning path. As an Amazon Associate, TechNodeX may earn from qualifying purchases.
TP-Link TL-SG108 8-Port Gigabit Switch
A simple way to build a small wired practice network at home.
Yubico YubiKey 5C NFC
A practical hardware key for learning strong account security habits.
Practical Malware Analysis
A deeper reference for defensive analysis and security lab thinking.