Skip to content
CyberEd DZ

Introduction to the SOC & Incident Response

Easy

The most realistic first cybersecurity job, and what the work actually is.

Courses:
11 sections
1.8 h
Intermediate English

Course content is in English (Intermediate English). The interface, summaries and glossary are in your language.

Log in to start this course

Log in

What you will be able to do

  • Triage an alert and decide severity
  • Reconstruct a timeline from logs
  • Write incident notes someone else can act on

Recommended background

These are suggestions, not requirements. You can start now.

Course outline

  1. Module 1

    What a SOC Does

    1. Roles and Tiers 8 min
    2. What the Job Is Actually Like 11 min
  2. Module 2

    Logs as Evidence

    1. Sources and Formats 8 min
    2. Timestamps and Time Zones 11 min
  3. Module 3

    Detection Basics

    1. Signatures vs Anomalies 8 min
    2. False Positives and Alert Fatigue 11 min
  4. Module 4

    Your Own SIEM

    1. Build a Minimal Log Pipeline Lab 8 min
    2. Ingest, Search, Alert 11 min
  5. Module 5

    Incident Response

    1. The IR Lifecycle 8 min
    2. Triage and Escalation 11 min
    3. Writing It Up 14 min

Written by CyberEd DZ