
SOC Analyst — career path
StationX Intermediate
The practical skills a security operations centre actually hires for. Security+ first, then defence, traffic analysis and detection, CySA+ to certify it, then forensics and malware analysis.
The path
Step 1 — Security foundation
The baseline every SOC hires for.
follows a certification path
Learn
- PathFollow the CompTIA Security+ (SY0-701) path — the entry certification for every blue-team role
Step 2 — Foundations of defence
Know what normal looks like before hunting for abnormal.
2 courses · 15 labs
Learn
- CourseSOC for Blue Teams 🔒 StationX Unlimited
11 sections · 21 lectures
- Training Overview 2
- Section : Introduction to Cyber Defense 2
- Section : Understanding Adversary Tactics 2
- Section : Roles and Responsibilities in Cyber Operations 1
- Section : Cyber Threat Landscape and Frameworks 2
- Section : Log Analysis and Threat Detection 2
- Section : Introduction to Malware Analysis 3
- Section : Malware Analysis Techniques and Tactics 2
- Section : Malware Analysis Process 1
- Section : Network and File-Based Malware Analysis 3
- Audio Version of Training 1
- CourseBlue Team Boot Camp: Defending Against Hackers 🔒 StationX Unlimited
6 sections · 60 lectures
- Training Overview 2
- Section 1: Introduction 3
- Section 2: Risk Analysis and Threat Intelligence 6
- Section 3: Endpoint Security 26
- Section 4: Network Security 13
- Section 5: Log Aggregation and Correlation 10
Practise
- Labs+Security Operations Practitioner — 15 labs 🔒 StationX Labs+
- Design, Defend, and Respond Across an End-to-End Security Architecture [Expert]
- Enforce Segmentation and Approved Access Paths [Guided]
- Establish a Windows Hardening and Security Logging Baseline [Guided]
- Establish centralized logging by onboarding hosts and validating monitoring readiness [Guided]
- Govern, Detect, Hunt, and Respond Through an Integrated Security Operations Sprint [Advanced]
- Governance and Compliance Evidence Collection [Guided]
- Harden a JumpBox for Secure Administration [Guided]
- Hunt Threats Using Intelligence and Rule-Based Detection [Guided]
- Implement TLS and Certificate Controls for a Service [Guided]
- Integrated Hardening Sprint A: Segment, Harden, and Secure Services [Advanced]
- Prioritize Risks and Implement One Remediation [Guided]
- Reduce DVWA Exposure by Using Compensating Controls [Guided]
- Secure Privileged Access and Auditing in Active Directory [Guided]
- Threat Modeling to Controls: Identify Risks and Implement Mitigations [Guided]
- Triage, Contain, and Automate Incident Response [Guided]
Step 3 — Traffic and network analysis
Read packets and spot malicious flows.
1 course · 26 labs
Learn
- CourseMaster Wireshark 3 in 5 Days 🔒 StationX Unlimited
6 sections · 34 lectures
- Training Overview 2
- Day One 3
- Day Two 8
- Day Three 7
- Day Four 7
- Day Five 7
Practise
- Labs+Introduction to Wireshark — 11 labs 🔒 StationX Labs+
- Can You Customize Profiles and Filters in Wireshark? [Advanced]
- Can You Display Customizations and Exploration of Captured Traffic by Using Wireshark? [Advanced]
- Can You Explore the Varied Uses of Wireshark? [Expert]
- Can You Extract Intercepted Files and Perform Password Attack Discovery? [Advanced]
- Implement Wireshark [Guided]
- Modify Display Filter Functionality [Guided]
- Perform an Effective Capture [Guided]
- Recreate Data Content [Guided]
- Recreate Data Flows [Guided]
- Use Display Filters [Guided]
- Use Wireshark to Discover Evidence of Network Attacks [Guided]
- LabsNetwork Forensics — 15 labs 🔒 StationX Unlimited
- Analyze Browser-based Heap Spray Attack
- Automated in-Depth Packet Decoding
- Clonezilla_Network
- Identifying Intrusion and Mitigating Attacks with RHEL Server
- Identifying Malicious Callbacks
- Identifying Malicious Network Connections
- Incident Detection and Identification
- Nexpose: Analysis & Reporting (Executive, High Risk and Recommendation Reporting)
- Parse Files Out of Network Traffic
- Searching for Indicators of Compromise
- Setting up Filters and Queries in Kibana
- Use pfTop to Analyze Network Traffic
- Verify Attributes of Identified SilentBanker Intrusion
- Verify Attributes of Intrusion Through Additional Analysis
- Windows Event Log Manipulation via Windows Event Viewer
Step 4 — Detection and monitoring
Find persistence by hand, then let AI speed the triage.
1 course · 12 labs
Learn
- CourseChatGPT for SOC Analyst: Master Cyber Security with AI 🔒 StationX Unlimited
7 sections · 59 lectures
- Training Overview 2
- A Sneek Peek into Cyber Security Mastery with ChatGPT 1
- Getting Started with ChatGPT for Cyber Security 17
- Advanced Prompts with ChatGPT 5 for Cyber Security Analyst 16
- Master Cloud Security with ChatGPT in Azure 11
- Enhance Incident Investigation with ChatGPT and SIEM Solution 11
- Audio Version of Training 1
Practise
- LabsRootkits & Threat Detection — 12 labs 🔒 StationX Unlimited
- Analyze Structured Exception Handler Buffer Overflow Exploit
- CTF Environment
- Creating a Case in FTK
- Detect Unauthorized Changes by Comparing to Approved Configurations
- Identify Rootkit and DLL Injection Activity
- Identifying Anomalous ARP
- Man In the Middle Crypto Attack
- Personal Security Products
- Snort Signatures, IDS Tuning, and Blocking
- Whitelisting & Suspicious File Verification
- x86 Buffer Overflows - Part 1
- x86 Buffer Overflows - Part 2
Step 5 — Analyst certification
Threat intelligence, SIEM, vulnerability management and incident response — certified.
follows a certification path
Learn
- PathFollow the CompTIA CySA+ (CS0-003) path — the intelligence, SIEM and incident-response labs live on this path
Step 6 — Incident response and forensics
Contain, eradicate, recover and evidence it.
1 course · 83 labs
Learn
- CourseDigital Forensics for Pentesters - Hands-on Learning 🔒 StationX Unlimited
18 sections · 67 lectures
- Training Overview 2
- Course Overview 1
- Building Your Forensics Lab Environment Using VirtualBox 6
- New Course Content 6
- Troubleshooting VirtualBox 2
- Introduction to Autopsy 4
- Kali forensic Mode 4
- CSI Linux Investigator 3
- Digital Forensics Case Management 1
- Open-source intelligence (OSINT) 3
- Using Shodan to Search for Vulnerable devices 3
- Computer Forensics 9
- Reverse Engineering and Malware Analysis 5
- Malware Hunting with Sysinternal Tools 3
- Stenography 2
- Network forensics Using Wireshark 7
- Practice What You learned 5
- Audio Version of Training 1
Practise
- LabsForensic Investigations and Evidence Handling — 13 labs 🔒 StationX Unlimited
- Analyze Packed Executable to Identify Attack Vector and Payload
- Analyze and Update a Company BCP/BIA/DRP/CIRP
- BCP DRP and Test Planning
- Creating a Case in Autopsy
- Creating a Case in OSF
- Creation of BCP and DRP
- FTK Analysis & Reporting
- FTK Enterprise Fundamentals and Mobile Investigation
- Metadata Extraction Lab
- Open Source Password Cracking
- Password Cracking with PRTK
- Registry Analysis
- Virtualization
- LabsCyber Defense Forensics Analyst Training Series — 70 labs 🔒 StationX Unlimited
- Analyze Malicious Network Traffic
- Auditing Service Accounts
- Auditing Service Accounts and Setting Up Automated Log Collection
- Baseline Systems in Accordance with Policy Documentation
- Conduct Root Cause Analysis for System Crashes
- Conduct Supplemental Monitoring
- Control Assessment and Evaluation
- Creating a Baseline Using Autopsy
- Creating a Case in FTK
- Creating a Forensic Image
- Creating a List of Installed Programs, Services and User Accounts from a WIN2K12 Server
- Cryptography: Steganography
- Cryptography: Using GPG for Encryption and Key Management
- Data Backup to Prep for Recovery
- Data Recovery with Autopsy
- Denial of Service PCAP Analysis
- Dynamic Malware Analysis
- Event Log Collection with Splunk
- Hash Verification
- Host Identification Scanning via Windows
- Host Identification Scanning with Linux
- Identify Access to a LINUX Firewall Through SYSLOG Service
- Implement Single System Changes in Firewall
- Import Nexpose Vulnerability Data into QRadar
- Intro to Linux - Routing and SSH Tunnels
- Introduction to Squert
- LNX101 - OpenSSH Installation, Configuration, and Hardening
- LNX101 - Setting Up a Firewall With UFW and Firewalld
- LNX101 - Telnet vs. SSH
- Lab Environment Orientation - *** (Start Here!) ***
- Live Imaging with FTK Imager Lite
- Log Event Reports
- Manual Vulnerability Assessment
- Manually Analyze Malicious PDF Documents
- Manually Analyze Malicious PDF Documents 2
- Manually Creating a Baseline with MD5Deep
- Memory Extraction and Analysis
- Nessus Scanning and Reporting
- Nexpose: Blue Team Remediation
- Overview of Kibana
- PAM Lab
- Parse Files Out of Network Traffic
- Participate in Attack Analysis Using Trusted Tool Set
- Patching With WSUS
- Pentesting & Network Exploitation - Linux Target Analysis Labs
- Preliminary Scanning
- Protect Against Beaconing
- Recover from Incident
- Recovery From Inadequate Patching
- Registry Analysis
- Rogue Device Identification and Blocking
- Scanning From Windows
- Scanning with Nmap
- Securing Linux - Firewalls
- Securing Linux for System Administrators
- Setting up Filters and Queries in Kibana
- Snap Exploit
- Snort Signatures, IDS Tuning, and Blocking
- Specialized Linux Port Scans
- Threat Designation
- Tweaking Firewall Rules for Detection
- Use pfTop to Analyze Network Traffic
- Using Snort and Wireshark to Analyze Traffic
- Validate Indications of Compromise: Analysis of PE File
- WebApp Attack PCAP Analysis
- Whitelist IP Address from IDS Alerts
- Windows Event Log Manipulation via Windows Event Viewer
- Windows System Hardening with Group Policy & Active Directory
- Windows System Hardening with PowerShell
- Wireshark
Step 7 — Malware analysis
Work out what a sample does.
1 course · 18 labs
Learn
- CourseIntroduction to Malware Analysis for Incident Responders 🔒 StationX Unlimited
7 sections · 24 lectures
- Training Overview 2
- Introduction 1
- Malware Concepts: Building a solid foundation upon which to learn 4
- Malware Analysis: Foundational concepts before begin working with malware 3
- Setting Up the Analysis Environment (FlareVM) 5
- Conducting the Analysis 8
- Conclusion 1
Practise
- LabsMalware Analysis & Reverse Engineering — 18 labs 🔒 StationX Unlimited
- Advanced Techniques for Malware Recovery
- Analysis and Recommendation Report
- Analyze DoomJuice Infection to Identify Attack Vector and Payload
- Analyze Malicious Activity in Memory Using Volatility
- Analyze and Classify Malware
- Conduct Root Cause Analysis for System Crashes
- Detect Embedded Shellcode in a Microsoft Office Document
- Dynamic Malware Analysis
- Fundamentals of Malware Analysis
- Linux Analysis
- Log Analysis
- MAC Analysis
- Practical Malware Analysis Labs
- Recover from Incident
- Remove Trojan
- Reverse Engineering Malware
- RootKit
- Validate Indications of Compromise: Analysis of PE File
Where this leads
- Threat Hunter — career path — Advanced
- Incident Responder — career path — Intermediate
- CISSP — Certified Information Systems Security Professional — Advanced
Advanced · after the job
The AI-Driven SOC Analyst
Senior roles are going to the people who can direct AI to build security solutions. When you're working in the role and ready for that step, the AI Master's Program is where it's taught — an advanced, application-only programme.
See the AI Master's Program →Application-only. A separate programme for when you're ready.