SOC Analyst & Blue Team Operations
Walk into a Tier-1 SOC role on day one
A 14-week course preparing you to triage alerts, investigate incidents, write detections, hunt threats, and run a SIEM end-to-end. Splunk + Sentinel + KQL + Sigma + ATT&CK detection engineering. Sources merged: CySA+, Blue Team Level 1 (BTL1), Microsoft SC-200, EC-Council CSA, LetsDefend SOC path, TryHackMe SOC L1.
Lessons
- The SOC Mission & Analyst Workflow
- Logs, Telemetry & SIEM Fundamentals
- Splunk & SPL Mastery
- Microsoft Sentinel & KQL
- Network Traffic Analysis
- Endpoint Detection (EDR + Sysmon)
- MITRE ATT&CK & Detection Engineering
- Threat Intelligence
- Phishing & Email Analysis
- Malware Triage
- Incident Response Process
- Threat Hunting
- Cloud SOC & Identity Monitoring
- Capstone: Full Investigation