Free SOC Analyst Training Course

Become a SOC Analyst in 10 Interactive Lessons

Master Splunk, Microsoft Sentinel, malware analysis, EDR hunting, and SOAR automation — with step-by-step walkthroughs written so a beginner can follow along. No videos required.

10
Interactive Lessons
8
Hands-On Labs
12+
Real Tools Covered
45 Qs
Bonus Interview Quiz

The Complete Curriculum

10 lessons covering everything from SOC fundamentals to advanced SOAR automation. Each lesson includes interactive walkthroughs with real commands.

Lesson 1
45 min

The Modern SOC Ecosystem

Interactive Reading

Deep-dive into Tier-1 SOC operations, alert triage, and the NIST 800-61 incident lifecycle. Learn what a Security Operations Center is, how alerts flow from detection to resolution, and the key tools you'll use daily.

SOC FundamentalsAlert TriageNIST 800-61SIEM Basics
Lesson 2
60 min

SIEM Engineering: Splunk Architecture

Hands-On Lab

Deploy a distributed Splunk environment from scratch. Configure indexers, forwarders, receiving ports, and the Splunk Add-on for Unix. Every command is explained step-by-step so a beginner can follow along.

SplunkSIEM ArchitectureLog Forwardinginputs.conf
Lesson 3
55 min

Advanced KQL for Microsoft Sentinel

Hands-On Lab

Master Kusto Query Language (KQL) for threat hunting in Azure logs. Write joins, summarize queries, brute-force detection rules, and anomaly hunts in OfficeActivity. Build your first automated analytics rule.

KQLMicrosoft SentinelThreat HuntingBrute Force Detection
Lesson 4
50 min

Network Forensic Analysis (PCAP)

Hands-On Lab

Reconstruct data exfiltration from raw packet captures using TShark. Extract HTTP files, find DNS tunneling signatures, follow TCP streams of reverse shells, and identify suspicious beaconing behavior.

TSharkPCAP AnalysisDNS TunnelingNetwork Forensics
Lesson 5
30 min

Incident Response Playbooks

Flashcards + Walkthrough

Memorize and apply the 6 NIST IR phases through interactive flashcards. Learn containment strategies, eradication techniques, and post-incident improvement — the foundation every SOC analyst needs.

NIST IRContainmentEradicationPost-Incident Review
Lesson 6
55 min

Malware Triage & Static Analysis

Hands-On Lab

Analyze a real Emotet sample. Calculate SHA-256 hashes, extract strings to find C2 URLs, examine PE headers for unusual sections, run Floss for obfuscated strings, and identify import table anomalies.

Malware AnalysisPE HeadersString ExtractionVirusTotal
Lesson 7
60 min

Dynamic Malware Analysis

Hands-On Lab

Run malware safely in a Cuckoo sandbox. Submit samples, analyze network API calls, extract dropped files, monitor registry changes, and identify mutex creation to fingerprint malware families.

Cuckoo SandboxDynamic AnalysisRegistry MonitoringMutex Analysis
Lesson 8
50 min

EDR Hunting: CrowdStrike Falcon

Hands-On Lab

Hunt threats using EDR process trees and telemetry. Query for suspicious cmd.exe launches, isolate compromised hosts, pull memory dumps via Real Time Response, and detect credential dumping with Mimikatz.

CrowdStrike FalconEDRProcess TreesCredential Dumping
Lesson 9
45 min

Threat Intelligence Platforms (MISP)

Hands-On Lab

Integrate MISP with your SIEM for automated IOC ingestion. Search existing threat intel, create new events for campaigns, export Snort/Suricata rules, synchronize external feeds, and tag with TLP.

MISPThreat IntelIOC ManagementSnort Rules
Lesson 10
55 min

Automated SOAR Playbooks (XSOAR)

Hands-On Lab

Build a Cortex XSOAR playbook for automated phishing triage. Extract email headers, check links against VirusTotal, set conditional severity logic, and auto-close low-severity incidents.

Cortex XSOARSOAR AutomationPhishing TriageVirusTotal API

Real Tools You'll Master

These are the exact tools used in professional Security Operations Centers worldwide.

Splunk
Microsoft Sentinel
KQL
TShark
Cuckoo Sandbox
CrowdStrike Falcon
MISP
Cortex XSOAR
VirusTotal
NIST 800-61
PE Headers
Floss
Bonus: Interview Prep Quiz

45 Questions. 6 Versions. Instant Scoring.

After completing the lessons, test yourself with the SOC Analyst Interview Bonus Quiz. It covers SIEM, Splunk, incident response, MITRE ATT&CK, threat hunting, IOC vs IOA, and more — with explanations for every answer.

Take the Quiz

Frequently Asked Questions

Do I need any prior experience to take this course?

No. Every lesson includes step-by-step walkthroughs written so a 15-year-old can follow along. You'll start with SOC fundamentals and build up to advanced threat hunting.

What tools will I learn?

Splunk, Microsoft Sentinel (KQL), TShark for PCAP analysis, Cuckoo Sandbox for malware analysis, CrowdStrike Falcon for EDR hunting, MISP for threat intelligence, and Cortex XSOAR for SOAR automation.

Is this course free?

Yes. The SOC Analyst course is available on the free Initiate tier. You can start Lesson 1 immediately — no credit card required.

How is this different from video-based training?

Instead of passively watching videos, you read interactive walkthroughs with real commands you follow along with. Research shows interactive text-based learning improves retention over passive video watching.

Does the course include interview prep?

Yes. After completing the lessons, you get a 45-question SOC Analyst Interview Bonus Quiz with 6 rotating versions covering SIEM, Splunk, incident response, MITRE ATT&CK, and more.

Will this help me get a job as a SOC analyst?

The course teaches the exact skills Tier-1 SOC analysts use daily. Combined with the interview quiz and resume builder, you'll arrive at interviews with real knowledge — not just certifications.

Ready to Start Your SOC Analyst Career?

Join iSET+ and get access to all 10 lessons, the bonus interview quiz, hands-on labs, and blockchain-verified credentials — all on the free tier.

Start Lesson 1 Free