Back to Course Library
BT
Intermediate18-24 hours

SOC & Blue Team

Practice defensive security operations: triage alerts, read SIEM evidence, map threat intelligence, operate incidents, preserve evidence, and hunt for suspicious behavior.

Course Overview

Start with the path, then open the rooms.

Work through the lessons in order. Each lesson starts with the concept, explains the vocabulary, then moves into examples, review checks, browser practice, and saved proof when it is useful.

6
Lessons
6
Knowledge checks
6
Practice tasks
6
Graded rooms

Outcomes

SOC Operations
Threat Hunting
SIEM
Incident Response
Industry Standards

SOC operations and incident handling

This course is organized around a role path, industry alignment, and proof a learner can keep.

Role path
SOC analyst
Career Paths
SOC Analyst / Incident Handler
Competency Focus
  • Separate signal, context, severity, uncertainty, and next action.
  • Use SIEM evidence and threat intelligence to decide close, monitor, or escalate.
  • Preserve incident and forensic evidence before recovery work.
  • Turn hunt hypotheses into repeatable detection improvements.
Work You Can Show
  • Triage notes with summary, severity, evidence, uncertainty, and next action.
  • SIEM, threat-intel, containment, forensic, and hunting plans with named owners or decisions.
  • Saved Check Work for defensive analyst reasoning.
Completion Gate

SOC rooms should require evidence-backed defensive action, preservation boundaries, and a severity-backed next step before completion.

Proof Loop

6 examples to inspect

Examples support the reading, but they are not completion evidence by themselves.

0/6 graded rooms passed

Check Work must pass inside the sandbox before protected rooms can complete.

0 explanations saved

Learners keep proof by writing expected result, actual result, and next improvement in their own words.