Tier 1 SOC Analyst Training Program
A rigorous 16-week program built on real enterprise tooling. Hands-on labs, live incident response, and a documented portfolio built for SOC roles across the US and Canada.
The essentials
What we're actually building here
We don't teach cybersecurity theory. We teach you how to work in a real Security Operations Centre. Every lab, every case study, every lecture is anchored to actual workflows you'll encounter on day one as a Tier 1 SOC analyst. If it's not something a real SOC does, we don't teach it.
The entire program runs on real enterprise tooling — Sentinel, Defender, CrowdStrike, and the platforms most North American SOCs actually deploy. You'll build KQL and FQL muscle memory through dozens of real-world detection scenarios. We teach you to think like an analyst: how to triage alerts, escalate incidents, and contain threats in minutes, not hours.
By the end of 16 weeks you won't just know cybersecurity — you'll know how to work in a SOC, and you'll have a documented incident portfolio to prove it. That's the difference between this program and everything else.
Skills you'll walk away with
Six core competencies, each built through hands-on investigation rather than slideware.
SOC Operations & Culture
Understand SOC structure, analyst roles, shift patterns, and the cadence of real security operations — plus the mindset that separates strong analysts from novices.
KQL & FQL Detection
Master Kusto and Falcon Query Languages from the ground up. Build detection rules, write analytic queries, and run alert triage at scale in Sentinel and CrowdStrike.
Identity Threat Detection
Recognize password spray, MFA bypass, phishing, AiTM attacks, and token theft. Tune Entra ID and Defender for Identity alerts and read sign-in logs like a pro.
Endpoint Defence & Response
Investigate alerts in Defender for Endpoint and CrowdStrike Falcon. Read process chains, file behavior, and network indicators, and contain a compromised host.
Threat Intelligence & Hunting
Work with indicators of compromise, threat feeds, and MITRE ATT&CK. Pivot from a single alert to a full investigation report and a proactive threat hunt.
Career Readiness
Full SOC shift simulations, mock interviews with real hiring managers, resume review, and a documented incident portfolio employers can evaluate on day one.
Who this is for
- Strong interest in cybersecurity and a commitment of ~6 hours per week — about 3 hrs theory (weekday evening) + 3 hrs lab (weekend)
- Basic understanding of IT — networks, operating systems, and log files
- Familiarity with Windows and command-line tools
- Access to Microsoft Azure, or willingness to use the free tier for labs
- Reliable internet and a quiet space to attend live sessions
- Prior security certifications (CISSP, CEH, etc.)
- Professional SOC experience
- Advanced coding or scripting skills
- Any prior knowledge of KQL, FQL, or Microsoft Sentinel
Roles you'll be ready for
Graduates target Tier 1 and analyst roles across North American security teams. Ranges reflect 2025 market data.
Tier 1 SOC Analyst
- Monitor and triage security alerts
- Investigate initial incidents
- Escalate to Tier 2 / 3 analysts
- Document and respond to threats
Security Analyst
- Deep-dive incident investigation
- Create and tune detection rules
- Build threat-hunting queries
- Produce threat intelligence reports
Threat Analyst
- Advanced threat research
- Indicator tracking and analysis
- MITRE ATT&CK mapping
- Strategic threat briefings
Ready to start your SOC career?
Applications for the next cohort are open and reviewed within 48 hours. No commitment to apply.