security cybersecurity

SOC Tier 1 — the job, done from the ticket in

Six tickets, handed to you cold, in the order and the format a real shift hands them over. You decide what matters first and then defend the decision. Analysis and defence only — nothing here teaches you to attack anything.

  • trending_upIntermediate
  • schedule7h 14m
  • menu_book12 lessons
  • publicEnglish
  • workspace_premiumBasic
SOC Tier 1 — the job, done from the ticket in

Briffing

Tier 1 is not a knowledge job. Almost every fact you need is on the screen in front of you. The job is deciding, under time pressure and with an incomplete picture, which of the eleven things in the queue you touch first, and being able to say why out loud to somebody who was not there. So this segment is built out of the actual queue. A CVSS 9.8 with seven unpatched hosts behind it. Twelve people who cannot log in and an Active Directory team insisting nothing is wrong. A service account authenticating successfully seven times in fifteen minutes, which no alert will ever fire on. Three overnight VPN sessions from cities nobody travelled to. A leaver with a USB stick. A payment that went out an hour ago on the strength of an email. Every ticket lands before the lesson, the same way it does at work: five to thirty minutes ahead, no briefing, no hint about which one it is. You write a short report. The lesson is the debrief. You will be wrong on at least two of them. One of the six has a model answer with no technology in it at all, and the fastest analyst in the room will be the one who picks up a phone. A note on two of the tickets: CVE-2026-41089 and CVE-2026-50751 are teaching artefacts. They are written to behave exactly like real advisories and the numbers are invented for this course. Everything else — the host names, the timings, the log lines — comes from tickets that were worked, then anonymised.

Amlinelliad y cwrs · 4 modules

lockYn datgloi gyda mynediad
  1. 01 What Comes First
    3 lessons·1h 32m

    Nothing in this module is about how the vulnerability works. You will not be asked to explain Netlogon. You will be asked which box gets patched at 09:15 and which one waits until Thursday, which is…

  2. 02 The Obvious Suspect
    3 lessons·1h 36m

    You are going to meet a symptom before you meet a cause, which is the normal order of events and the one every training course gets backwards. The skill being trained is asking for the right next…

  3. 03 When Nothing Fails
    3 lessons·1h 59m

    Everything you have looked at so far announced itself. This module is the opposite case: a log where every single line is a success, and a VPN gateway where the sessions are valid. CVE-2026-50751 is…

  4. 04 Saying It So Somebody Acts
    3 lessons·2h 7m

    Unresolved items first. Every item labelled ongoing or completed. Human language throughout — "someone's Windows PC", not "the endpoint". You will record yourself, listen back, and record it again,…

Cwestiynau a ofynnir yn aml

Beth a ddysgaf yn SOC Tier 1 — the job, done from the ticket in?
Six tickets, handed to you cold, in the order and the format a real shift hands them over. You decide what matters first and then defend the decision. Analysis and defence only — nothing here teaches you to attack anything.
A oes angen profiad blaenorol arnaf?
Argymhellir rhywfaint o wybodaeth flaenorol cyn dechrau SOC Tier 1 — the job, done from the ticket in.
Pa mor hir y mae SOC Tier 1 — the job, done from the ticket in yn ei gymryd?
Mae SOC Tier 1 — the job, done from the ticket in yn cynnwys 4 modules ac 12 lessons. Rydych chi'n dysgu ar eich pace eich hun.
Sut rydw i'n cael mynediad?
Mae SOC Tier 1 — the job, done from the ticket in yn cael ei gynnwys gydag unrhyw danysgrifiad talu.

Mwy yn Amddiffyn Cyber

Am I Too Late? — The Honest Map Into Cyber
Beginner Am I Too Late? — The Honest Map Into Cyber The four questions people actually ask before they book: is forty too late, do I need to code, what do I need before I start, and which certificate. Answered plainly, with a role map, real first-year pay, and a written plan you leave with.
The Kid Who Wants To Hack
Intermediate The Kid Who Wants To Hack You want to know how attacks work. Fine. This segment teaches you to see them — in a domain record, in a DNS lookup, in a log file — and to build a tool that scores a link before anyone clicks it. Nothing here teaches you to attack anything, and by the end you will understand why that is the expensive skill.
Beginner The CV and the Application One page, built for somebody entering security without a security job history. Six adverts read line by line, the artefact put where a job history would go, the write-up marked, and the funnel tracked honestly — including what sixty rejections do and do not tell you.
Career Changer's Lab — build the machine you'll learn on
Beginner Career Changer's Lab — build the machine you'll learn on Build the machine you are going to learn on, from a laptop that currently has nothing on it. A hypervisor, a Kali virtual machine, snapshots, Linux from the ground up, and a written procedure for rebuilding all of it from nothing. Lab construction and fundamentals only — nothing here teaches you to attack anything.
Intermediate The Security Interview Four rooms, each testing something different. What the recruiter screen is actually filtering, and the salary range asked before anything else. The technical bank, with a model answer and the reason it works. Five scenario questions marked the way a hiring manager marks them. Then the panel, the questions you ask them, and the debrief you write the same evening.