Cyber Security Operations Analyst
This associate-level path prepares learners to work in a Security Operations Center. It teaches how alerts are produced, how logs should be interpreted, how network and endpoint evidence are correlated, and how to escalate findings in a clear analyst report. The emphasis is on disciplined triage: identify what happened, decide whether it matters, preserve useful evidence, and communicate the next action.
SOC Fundamentals & Alert Triage
SOC Architecture, Analyst Tiers & the Alert Lifecycle
MITRE ATT&CK: Mapping Events to Tactics & Techniques
Windows Event Log Investigation: Authentication & Persistence Detection
SIEM Investigation: Detecting Ransomware Pre-Deployment Activity
Log Analysis & Detection Engineering
Network Detection: C2 Beaconing & DNS Exfiltration in SIEM
SIEM Investigation: Web Application Attack Chain Detection
Detection Engineering: Writing and Tuning Sigma Rules
Network Forensics: PCAP Analysis for SOC Investigations
Network Evidence & Threat Enrichment
SIEM Investigation: DNS Exfiltration Trace
IOC Enrichment & Applied Threat Intelligence for SOC Analysts
SOC Capstone: End-to-End Investigation from Alert to Report
CTFFactory Cyber Security Operations Analyst — Associate
Associate credential — awarded upon completion