
Build strong networking and security foundations for a soc analyst role, and learn to work with data sources, logs, dashboards, alerts, encryption, hashing, and incident response through ransomware scenarios.
Hubs broadcast to all devices in a local area network, while switches use MAC addresses to deliver data to the correct device. Routers connect networks and route IP ranges.
Explore the difference between public and private IP addresses, including private ranges 192.168.x.x, 10.x.x.x, and 172.16.x.x to 172.31.x.x, how ISPs assign public IPs, and why NAT uses private addressing for networks.
Explain how network address translation and port address translation map private IP addresses to a single public IP, allowing internal devices to reach the internet while hiding internal details.
Explore common port numbers and transport layer basics, including ftp 20/21, http 80, https 443, dns 53, imap 143, smb 139/445, telnet 23, rdp 3389, syslog 514, and tcp/udp distinctions.
Position the firewall as the first line of defense, filtering inbound and outbound traffic between external networks and internal network using source, destination, and port rules to allow or block.
Explore how a virtual private network creates a secure tunnel between your device and your organization's private network. Authenticate with credentials and route traffic through organization's proxy for controlled access.
Explore the basics of cryptography, contrasting symmetric and asymmetric encryption, and learn how encryption and decryption with public and private keys protect data.
Explain the CIA triad by showing how confidentiality uses encryption, integrity relies on hashing, and availability achieves resilience through data replication and redundant, load-balanced servers.
Explore how ssl secures data and how https pairs http with ssl/tls, distinguishing secure http traffic from unsecured http, and noting ports 80 and 443.
keep up with cyber security news and latest attacks by following CERT and US-CERT feeds, analyzing indicators of compromise like hashes and IPs, and monitoring zero-day vulnerabilities and CVE records.
The lecture contrasts virus and worm, explaining that viruses infect a single machine and disrupt software, while worms replicate across networks, locating shared folders and spreading to other computers.
Explore how SQL injection attacks manipulate web applications to access databases, bypass authentication with boolean conditions like 1=1, and how to detect and prevent such threats.
botnets unleash distributed denial of service by using a command and control center to instruct compromised devices to flood a server with requests, masking malicious traffic as normal users.
Learn how brute force attacks use username and password lists to trigger rapid failed logins, and how firewalls and Splunk analytics detect and stop them.
Explore core networking concepts for cyber security interviews, including OSI layers, TCP/IP vs UDP, routing, DNS, ports, firewalls, encryption, hashing, vulnerability assessment, and defense in depth.
Explore the five stages of cyber attacks—reconnaissance, weaponization, delivery, exploitation, and command and control—along with key concepts like brute force, dictionary attacks, pass the hash, and zero-day vulnerabilities.
Explore spoofing techniques (wifi, ip, mac, dns, email) and phishing variants (spear, whaling), and learn mitigation through user awareness, email security, and rate limiting.
Explore ARP spoofing and DNS poisoning, revealing how man-in-the-middle attacks hijack IP and MAC addresses, with mitigations like static IP addressing, DNS transfer controls, and log monitoring.
Learn the OWASP top 10 web application security risks, focusing on injection (SQL injection) and cross-site scripting, and apply mitigations like input validation, sanitization, encoding, and cookies and tokens.
Learn how SIEM systems collect and parse logs from diverse sources, normalize and structure events, and use aggregation and correlation to detect and alert on suspicious activity.
Explore SIEM dashboard and use cases, learning how to generate alerts, dashboards, and reports from queries, and monitor technology, proxy, and authentication data, including malware infections and threat intelligence.
Monitor event logs across operating systems for user groups, account changes, logon patterns, service activity, and security events, including database, firewall, antivirus, vulnerability scans, and dlp.
Security operations center maintains the organization's security posture by monitoring the perimeter firewall, antivirus tools, and proxy tools, and by handling alerts and responding to incidents.
Discover the security architecture from isp and edge routers to perimeter and internal firewalls, dmz, and application load balancers, and how soc analysts analyze logs to block traffic.
Explore how a SoC team operates within an organization, detailing the SoC manager, multiple leads, L1–L3 engineers, and the incident handling workflow, playbooks, and cross-team collaboration.
Master the 24/7 SOC engineer roles, including continuous monitoring, alerts, incident handling, L1-L3 responsibilities, dashboards, threat hunting, data sources onboarding, and knowledge transfer for secure operations.
Identify and compare in-house, MSP, and hybrid security operations center models, focusing on resources, skills, commitment, log sources, and centralized monitoring for proactive incident response.
Learn to create a ServiceNow security incident from alerts or analysis, fill fields like incident number, assignment group, affected resources, and priority, and drive the lifecycle from new to resolved.
Explain service level agreements for SOC incidents, outlining response times, initial analysis windows, and paging and escalation for B1/B2 and P3 alerts, plus cross-team coordination.
Analyze false positive analysis in security operations, detailing true/false outcomes, true positives, false positives, and false negatives, and explain how alerts indicate attacks or not.
Identify log sources such as linux and windows servers, firewalls, web applications, and databases, monitor about 1,500 servers with 250–300 gb of logs daily, and expect 60–70 alerts after tuning.
Explore the incident response lifecycle—from preparation and identification to containment, remediation, recovery, and lessons learned—covering incident handling, phishing defenses, and cross-team coordination.
Upon an alert, evaluate validity and decide if it’s a false positive or an incident. If real, create an incident in ServiceNow, assign teams, and implement containment, forensics, and remediation.
Master shift handovers in a cyber security SOC by documenting incident analysis, monitoring dashboards, and daily reports to ensure seamless transition and continuity between shifts.
Learn how to classify incidents as P1–P4, prioritize responses, and lead cyber security incident calls with L1–L3 roles, while coordinating stakeholders, incident charts, and timely updates within 15–30 minutes.
Analyze brute force alerts by evaluating login attempts, distinguishing failed from successful logins, and tracing source IPs and usernames across logs.
Perform initial malware alert analysis by gathering computer name, user, IP, file name, hash value, malware type, and then check antivirus detection and sandbox results before remediation.
Analyze phishing emails from header to attachment using email gateway logs and firewalls, validate SPF/DKIM/DMARC, and use tools like MX toolbox and sandboxing to identify indicators of compromise.
Analyze sql injection attacks by following an investigation: verify IP reputation, review web and database logs, assess whether commands were executed, and implement mitigations like input validation and IP blocking.
Analyze DDoS attack indicators by reviewing suspicious traffic, botnet sources, and logs from firewalls, IDS, and web servers. Identify source IPs, countries, and patterns to guide ISP or cloud-based mitigations.
Investigate suspicious outbound traffic by checking the IP reputation using firewall log sources, then block the IP, remove malicious files, disable affected accounts, and ensure systems are patched.
Due to the rapid increase in data breach incidents and sophisticated attacks, organizations are investing heavily in technologies and security solutions. The deployment of a security operation center (SOC) is a cost-effective strategy against these cyber threats. The SOC team deals with security incidents within the organization. The SOC analyst plays a vital role in the SOC team by monitoring the log data, identifying suspicious activities, and reporting to the higher authorities. It could be an excellent platform to start your career in cybersecurity. A candidate must have a basic knowledge of networking, malware analysis, and incidence response.
The cyber security field is one of the most booming fields in this decade. To get a job in this field, it depends on the kind of profile you are looking in the cyber security domain as this field has many different kinds of job roles.
SOC Analyst
SOC analysts are the first to respond to cyber security incidents. They report on cyberthreats and implement any changes needed to protect the organization. Job duties of SOC analysts include: Threat and vulnerability analysis. ... Analysis and response to previously unknown hardware and software vulnerabilities.
That said, it's not unusual for a Tier 1 SOC Analyst gig to be your first stop in the journey of your cybersecurity career. While every employer will attach a slightly different set of duties to any given job title, in general there are three tiers of SOC analyst jobs. The EC-Council's blog has a detailed breakdown of the differences among those tiers, but to sum up:
L1 SOC analysts are triage specialists who monitor, manage, and configure security tools, review incidents to assess their urgency, and escalate incidents if necessary.
L2 SOC analysts are incident responders, remediating serious attacks escalated from Tier 1, assessing the scope of the attack and affected systems, and collecting data for further analysis.
L3 SOC analysts are threat hunters, working proactively to seek out weaknesses and stealthy attackers, conducting penetration tests, and reviewing vulnerability assessments. Some Tier 3 analysts focus more on doing deep dives into datasets to understand what's happening during and after attacks.