Defense & Detection
SOC operations, logging, SIEM, and the incident response lifecycle.
What you'll actually learn
A SOC analyst's real job isn't watching a dashboard turn red — it's deciding, out of thousands of daily log events, which handful actually matter. This track builds that judgment from the ground up: how logs from different systems get normalized and correlated in a SIEM, what an alert actually represents versus what it claims to represent, and the incident response lifecycle that turns "something looks wrong" into a documented, contained, and resolved event.
What you'll be able to do
You'll take a raw pile of log data with a real intrusion buried in it, and work the actual detection path — spot the anomaly, correlate it across systems, and follow the incident response lifecycle through containment instead of just identification. That's the skill that separates someone who can read a SIEM dashboard from someone a SOC can actually trust on a live incident.
Syllabus
Frequently asked
Roughly 2 hours across 9 hands-on quests — you can go at your own pace and pick up exactly where you left off.
You should be comfortable with Hardening Linux Systems first — the skill tree unlocks Defense & Detection once you've cleared those.
Yes — Defense & Detection is fully available on the free tier, starting with a free first quest and no payment method required to sign up. Plus and Elite remove pacing limits but don't gate any of the Defense & Detection curriculum behind a paywall.
Create a free account and begin your first quest — no card required.
Start free