SecAITech Learn

SOC Analyst (Cybersecurity)

Watch for attacks, investigate security alerts, and help stop incidents as part of a Security Operations Center team.

Time needed
6 to 9 months at about 2 hours a day
Who it's for
People comfortable with computers who enjoy investigating. IT or networking experience helps.
Steps
6
  1. Step 1: Networking and Linux basics

    5 to 6 weeks

    Learn how networks work: IP addresses, ports, DNS, HTTP, and TCP. Get comfortable on the Linux command line, because most security tools and logs live there.

  2. Step 2: Security fundamentals

    4 to 5 weeks

    Learn the core ideas: confidentiality, integrity, availability, common attacks, malware types, authentication, and encryption basics.

  3. Step 3: How attackers operate

    3 weeks

    Study the tactics and techniques real attackers use, so you can recognise them in logs. MITRE ATT&CK is the common language security teams use.

    • MITRE ATT&CK Documentation, English, free Start with the Enterprise matrix. Pick five techniques and learn how each looks in logs.
  4. Step 4: Logs, SIEM, and alert investigation

    6 to 8 weeks

    Practise investigating alerts in realistic labs: read Windows and Linux logs, search in a SIEM, and decide whether an alert is a real attack. Write short reports for each investigation.

    • TryHackMe Practice, English, paid The SOC Level 1 path is a strong structured option. Some rooms are free.
    • LetsDefend Practice, English, paid Simulated SOC alerts to investigate. Has a free tier.
    • Blue Team Labs Online Practice, English, paid Investigation challenges. Has free challenges.
  5. Step 5: Detection rules

    3 to 4 weeks

    Learn to write rules that catch attacks automatically. Sigma is a shared rule format that converts to many SIEMs. Read existing rules, then write your own for techniques you studied in ATT&CK.

  6. Step 6: Portfolio and job applications

    2 to 3 weeks

    Publish three or four investigation write-ups and a few detection rules on GitHub or a blog. Explain what you found, how, and what you'd recommend. This shows employers how you think.

Want a teacher, feedback, and a real project?

SecAITech Academy runs small, practical batches where you build real work, get your code reviewed, and finish with a verifiable certificate.

See Academy batches