Cybersecurity
SOC Analyst Level 1: Blue Team Fundamentals
Work real alerts, triage like an analyst, and document what you found.
- 12 modules
- 18 labs
- ~24 hours
- Beginner

- Hands-on Labs
- Projects
- Certificate
- Beginner Friendly
Course overview
This course takes you through the day-to-day reality of a Tier 1 security operations analyst: ingesting logs, tuning noisy detections, triaging alerts, and escalating with evidence that a Tier 2 analyst can actually act on.
You build your own detection lab, generate real telemetry from Windows and Linux endpoints, and write the queries, notes and incident reports that make up an analyst's portfolio.
What you will be able to do
- Read and interpret Windows, Linux, firewall and cloud logs with confidence
- Write detection queries and tune out false positives
- Run a structured alert triage workflow end to end
- Map observed activity to MITRE ATT&CK techniques
- Write incident notes and handover reports an employer would accept
Curriculum
- 1
Security Operations Foundations
How a SOC is structured and where a Tier 1 analyst fits.
- SOC tiers and escalation paths
- Alert lifecycle
- Shift handover discipline
- 2
Logging & Telemetry
Where the evidence comes from and how to collect it.
- Windows event logs
- Sysmon configuration
- Linux auditd and syslog
- Log forwarding
- 3
Build Your SIEM Lab
Stand up a working SIEM and pipe real telemetry into it.
- Lab architecture
- SIEM install and hardening
- Agent onboarding
- Index and parsing sanity checks
- 4
Detection Engineering Basics
Turn attacker behaviour into queries and rules.
- Query language fundamentals
- Writing your first detections
- Tuning false positives
- Detection documentation
- 5
Threat Detection with MITRE ATT&CK
Cover the techniques that actually show up in alerts.
- Initial access and execution
- Persistence and privilege escalation
- Credential access
- Coverage mapping
- 6
Incident Response & Reporting
Contain, document, and hand off.
- Triage workflow
- Containment decisions
- Evidence collection
- Writing the incident report
Labs you will build
PrimeSec does not hand you a pre-built machine. You get professional lab guides and build the environment yourself — that is where the skill comes from.
- Build a Windows + Linux detection lab in your hypervisor
- Deploy Sysmon with a tuned configuration
- Onboard endpoints into your SIEM
- Simulate brute-force authentication and detect it
- Detect suspicious PowerShell execution
- Investigate a phishing-to-execution alert chain
- Tune a noisy detection down to actionable volume
- Produce a full incident timeline from raw logs
Portfolio projects
- SOC lab build documentation with architecture diagram
- A detection rule pack with rationale and ATT&CK mapping
- A complete incident report for a simulated intrusion
Frequently asked questions
Do you provide the lab environment?
No — and that is intentional. PrimeSec gives you professional lab guides that teach you to build and configure the environment yourself using your own machine, Hyper-V, VMware, VirtualBox, Docker, or a cloud free tier. Building and troubleshooting the environment is part of the skill.
Is this course self-paced?
SOC Analyst Level 1 is self-paced. Lessons, knowledge checks, labs and projects unlock in order so you always know what to do next.
Do I get a certificate?
You receive a PrimeSec course completion certificate once every module, lab and project requirement is met. It demonstrates completion and practical work — not an accredited industry certification.
Will cloud labs cost me money?
Labs are designed around free tiers and local virtualisation wherever possible, and every cloud lab includes cleanup steps so you do not leave billable resources running.
Related courses
Network Security
Network Security Essentials
Beginner · 8 modules · 12 labs
GRC & Compliance
GRC & Compliance Foundation
Beginner · 6 modules · 10 labs
Cloud Security
AWS Security Essentials
Beginner · 10 modules · 16 labs
