Learn the job a SOC actually does: read logs on the command line, hunt attacks with MITRE ATT&CK, write Splunk and Sentinel detections, and run an incident end to end. Build the portfolio that lands a remote blue team role.
Who this is for: Beginners aiming for a remote SOC analyst / blue team role.
The outcomes
What you will walk away with
Three artefacts you build and keep. One certificate to prove it.
01
SOC triage notes (template)
A fill-in incident triage notes template you can copy for every alert you work. It captures the alert summary, the date, time and time zone, the source and destination, the indicators of compromise, exactly what you checked and the commands you used, the severity, the decision to escalate or close, and the next steps, so your write-up is consistent and hands over cleanly.
Week 2Yours to keep
02
Detection query cheat sheet (SPL and KQL)
A side by side reference of common SOC detections written in both Splunk SPL and Microsoft Sentinel KQL, covering failed logins, brute force, new admin and rare process, with a reminder to adapt every query to the local data model.
Week 3Yours to keep
03
SOC capstone and interview pack (templates)
A two-part pack. Part A is a capstone: investigate a supplied multi-log scenario (an SSH authentication log plus a matching SIEM brute-force alert), reach a verdict and write a full incident report using the fill-in template, then mark yourself against a clear 20-point rubric. Part B is a SOC interview prep worksheet: a prep checklist, three STAR story slots with prompts, a SOC topics revision tracker, and questions to ask the interviewer.
Week 4Yours to keep
Then the certificate that proves it all
Every artefact above rolls up into a verifiable credential with its own serial number and public verification page. Your board can check it. Anyone can.
The curriculum
What you learn, module by module
What a Security Operations Centre is, how the tiers and the alert lifecycle work, where blue, red and purple teams fit, why the work is remote-friendly, and the honest path into a first SOC analyst role: the tools, the certification ladder and a realistic pay picture.