Hacker AcademyHacker Academy

Blue team training path

SOC Analyst Training Path

A practical pathway focused on monitoring, investigations, endpoint visibility, SIEM workflows, and security operations fundamentals.

Path overview

Blue team and security operations skills

SOC workflows
SIEM and Splunk
EDR concepts
Alert investigations
Mentor-supported learning

This path is designed for learners who want practical exposure to security operations, monitoring, investigations, and defensive security workflows.

SOC analyst training session
Alert triageSIEM practiceInvestigation habits

Path snapshot

SOC Analyst Path

Develop the practical skills needed to monitor, investigate, and respond to security events.

Level

Beginner to Intermediate

Duration

10–14 weeks part-time

Modules

6 included

Who this is for

Designed for future SOC analysts and blue team learners

This path is suitable for learners who want practical exposure to monitoring, investigations, SIEM platforms, endpoint visibility, and security operations workflows.

Career changers entering cyber security

IT professionals moving into SOC roles

Junior analysts building practical blue team skills

Modules included

Build practical security operations capability

The path combines infrastructure, endpoint security, SIEM, and monitoring-focused modules from the wider cyber security engineering curriculum.

Network Fundamentals

Build the networking knowledge needed to understand protocols, services, ports, traffic flows, segmentation, and packet analysis.

TCP/IPDNSHTTPPortsWireshark

Linux Fundamentals

Develop practical Linux knowledge including command-line usage, permissions, processes, packages, and remote access.

CLIPermissionsProcessesPackagesSSH

Windows Fundamentals

Understand Windows Server, administration tools, PowerShell, Active Directory, users, groups, and enterprise Windows concepts.

Windows ServerPowerShellADLDAP

Introduction to Cyber Security

Learn core cyber security concepts including threats, malware, CIA triad, attacker behaviour, cyber kill chain, and IAM concepts.

CIA triadMalwareKill chainIAM

EDR

Understand endpoint protection, policies, alerts, device isolation, runtime protection, threat graphs, and endpoint investigation workflows.

AlertsThreat graphsIsolationDLP

SOC / SIEM / Splunk

Develop practical monitoring and investigation skills using SIEM concepts, Splunk, log analysis, SPL, and alert workflows.

SOCSIEMSplunkSPLInvestigations

Practical work

Practical work you will do

The emphasis is on the daily investigation habits a SOC analyst needs, not just tool familiarity.

Triage alerts and decide what needs investigation
Use SIEM queries to follow suspicious activity
Connect endpoint telemetry with user, host, and network context

Skills you will build

Practical monitoring and investigation capability

The goal is to help learners understand how modern security operations teams monitor environments, investigate activity, and respond to potential threats.

Understand SIEM and SOC operational workflows
Investigate alerts and suspicious activity
Use Splunk and basic SPL queries
Understand endpoint telemetry and EDR concepts
Recognise attacker behaviour and common indicators
Build practical security operations awareness

Prerequisites

Start at the right level

Foundation modules can be added or removed depending on the learner’s existing technical knowledge.

Recommended before starting

  • Basic computer knowledge
  • Basic networking awareness
  • Interest in monitoring and investigations

Add these if needed

  • IT Fundamentals
  • Network Fundamentals
  • Windows Fundamentals

Useful optional foundation

  • Linux Fundamentals
  • Cryptography
  • Cloud fundamentals

Delivery model

Guided training, labs, and instructor support

Learners follow structured content, practical exercises, SIEM-focused workflows, and mentor support designed to help build operational confidence.