BBuddyAI Learn
Cybersecurity · Beginner → Expert

🛰️ SOC Analyst and Security Operations

Develop blue-team skills for monitoring, SIEM, endpoint and network telemetry, detection engineering, threat intelligence, triage, incident response and reporting.

Course roadmap

Pass each module exam to unlock the next module.

Module 1 · Beginner

SOC Operations, Roles, Escalation and Case Management

Locked
Module 2 · Beginner

Security Logs, Telemetry and Event Normalization

Locked
Module 3 · Beginner

SIEM Architecture, Search and Correlation

Locked
Module 4 · Beginner

Windows Security Events and Endpoint Telemetry

Locked
Module 5 · Intermediate

Linux Logs and Server Telemetry

Locked
Module 6 · Intermediate

Network Security Monitoring and Traffic Analysis

Locked
Module 7 · Intermediate

Email Security and Phishing Investigation

Locked
Module 8 · Intermediate

Identity, Authentication and Cloud Audit Events

Locked
Module 9 · Advanced

Detection Engineering and Alert Logic

Locked
Module 10 · Advanced

Threat Intelligence and Indicator Handling

Locked
Module 11 · Advanced

Alert Triage, Scoping and Prioritization

Locked
Module 12 · Advanced

Malware Triage and Safe Analysis Concepts

Locked
Module 13 · Expert

Incident Response Containment and Eradication

Locked
Module 14 · Expert

Threat Hunting Methodology

Locked
Module 15 · Expert

Reporting, Evidence and Metrics

Locked
Module 16 · Expert

Expert Capstone: SOC Investigation Simulation

Locked
Certification gate

Final course exam

Pass mark: 80%. Time limit: 360 minutes. All module exams must be passed first.

Locked until modules are passed