CybersecurityBeginner
SOC: First 30 Days
From alert triage to containment and hardening — the minimum viable skill set for a junior SOC analyst.
6 steps~8h
Back to labs
- 1Read
Incident response playbook
Learn the first-30-minutes workflow: triage, scope, preserve evidence, contain.
Open chapter - 2Read
Linux hardening baseline
CIS-aligned controls you can apply on a fresh server before it touches production.
Open chapter - 3Checklist
SOC triage checklist
- ›Validate alert severity (P1/P2/P3) against defined criteria
- ›Confirm false-positive sources (patch window, scanner, pentest)
- ›Preserve SIEM query URL and raw logs before any containment
- ›Assign incident roles: IC, scribe, comms
- 4Lab
Mini lab — phishing triage
- ›In a VM lab, ingest a sample phishing alert JSON
- ›Identify entry vector, affected account, and active C2 indicators
- ›Draft a containment plan without executing destructive actions
- ›Document rollback steps if containment is wrong
- 5Read
GenAI data leakage risks
Understand what ops teams paste into public LLMs and why browser-layer DLP matters.
Open chapter - 6Self-check
Self-check — SOC foundations
Answer all questions to validate this step