Courses / On-demand courses
SOC Analyst Essentials
Detect, triage and respond to real attacks the way a security operations centre does.
SOC Analyst Essentials is a self-paced online course: 9.5 hours of recorded sessions across 7 modules, with 6 graded by Nova, Square 1's AI tutor. The founding price is A$45, down from A$90. Start any time and keep your own pace.
Price: A$45A$9050% off
Founding price for the first cohort, until 21 October.
Founding price, one payment. Founding students keep their founding price on any second programme.
Founding intake
Spot holders hear the start date first.
Module by module
Module 1 · 60 min
Inside a SOC: alerts, tiers and shifts
Module 2 · 90 min · graded
Logs that matter: endpoints, network, cloud
Module 3 · 90 min · graded
SIEM searches and detections
Module 4 · 60 min · graded
Triage: true, false or not sure
Module 5 · 90 min · graded
Incident response from first alert to close
Module 6 · 60 min · graded
AI in the SOC
Module 7 · 120 min · graded
Project: a simulated attack, detected and handled
- recorded hours
- 9.5
- modules, in order
- 7
- deployed projects
- 3
- graded checkpoints
- 6
Who it is for, and what you receive.
People comfortable with computers and networks who want to work in a security operations centre: detecting, triaging and responding to real attacks. No security background needed.
Before you start
Comfortable with computers and networks; no security background needed.
Skills
- SIEM
- log analysis
- detection engineering
- triage
- incident response
- 1
The recorded sessions
Taught by an instructor, taken in order at your own pace, yours for twelve months.
- 2
Graded work after every module
Exercises and projects marked by Nova against a rubric you can read, with what you did well and what to fix.
- 3
The projects
Deployed and graded, each one on your record with its repository.
- 4
Your hiring plan
The same six-part plan the bootcamps use, run with the career agent.
- 5
The record and the certificate
Every grade at square1ai.com/u/{handle}; a credential ID that resolves at square1ai.com/verify.
- 6
Nova as your tutor
Help that is about your actual work, because it has read all of it.
The content plan, module by module.
9.5 recorded hours from an instructor, taken in order at your own pace. Nova grades the work at the end of each module.
Inside a SOC: alerts, tiers and shifts
Module 1 · 60 min
Watch and take notes; nothing to submit in this module.
- Python
- Azure
- AWS
What a SOC does
Tiers and escalation
Shift handovers
Logs that matter: endpoints, network, cloud
Module 2 · 90 min
Graded at the end: A log source onboarded and parsed.
- Python
- Azure
- AWS
Windows and Linux logs
Network logs
Cloud audit logs
SIEM searches and detections
Module 3 · 90 min
Graded at the end: Three detections written and tested.
- Python
- Azure
- AWS
Search languages
Writing a detection
Testing against known attacks
Triage: true, false or not sure
Module 4 · 60 min
Graded at the end: Twenty alerts triaged with reasons.
- Python
- Azure
- AWS
Context and enrichment
False-positive patterns
Writing up the decision
Incident response from first alert to close
Module 5 · 90 min
Graded at the end: An incident handled with a timeline.
- Python
- Azure
- AWS
Containment
Eradication and recovery
The timeline and report
AI in the SOC
Module 6 · 60 min
Graded at the end: An AI-assisted triage you checked by hand.
- Python
- Azure
- AWS
Summarising alerts
Checking the assistant
What not to hand over
Project: a simulated attack, detected and handled
Module 7 · 120 min
Graded at the end: The detections, the timeline and the incident report.
- Python
- Azure
- AWS
The attack
Detection
Response
The report
The projects.
Each is deployed and graded by Nova against a rubric you can read before you start.
- 1
Detections in a SIEM
Onboard endpoint and network logs into a free SIEM, then write three detections for common attacks and test each against a recorded attack.
You hand in
- Log onboarding notes
- Three detection rules
- Test evidence for each
The rubric requires
Each detection fires on its recorded attack and stays quiet on normal traffic.
- 2
An alert queue, triaged
Work a queue of twenty realistic alerts, decide true, false or uncertain for each, and write the reason and next step a teammate on the next shift could act on.
You hand in
- Triage log
- Escalation notes
- Shift handover
The rubric requires
Your decisions match the answer key on true positives and every decision has a reason.
- 3
A simulated attack
A simulated intrusion runs in a lab environment. Detect it, contain it, build the timeline from the logs and write the incident report for a manager and for engineers.
You hand in
- Detection evidence
- Incident timeline
- Incident report
- Lessons learned
The rubric requires
The timeline matches the simulation's ground truth on every key step.
What you can do at the end.
Detections, triage and an incident you handled end to end, and three graded projects on your record that show it.
- 1
Explain how a SOC works: alerts, tiers, shifts and handovers.
- 2
Onboard and read the log sources that matter for detection.
- 3
Write and test SIEM detections for common attacks.
- 4
Triage alerts as true, false or uncertain, with reasons.
- 5
Handle an incident from first alert to close with a timeline.
- 6
Use AI to speed up triage and check its work by hand.
Roles this prepares you for
- SOC analyst
- Security analyst
- Incident responder (junior)
No placement rate is shown, because there are no graduates to count yet. The roles above are what the projects are built for.
Your record at the end.
Every exercise and project is graded by Nova against a rubric you can read, and every grade is kept on one page an employer can open and run. This is what the programme writes to it.
- Graded, line by line
- Nova reads every submission against the brief and the rubric and returns a score, what you did well and what to fix.
- Module by module
- Each module ends in graded work; the next opens when you are ready, on your own schedule.
- Nova remembers
- Help is about your actual work, because the tutor has every submission and every failed exercise of yours.
- One page an employer can run
- Every grade and project at /verify. An employer opens it and runs the code.
Record, SOC Analyst Essentials
Example
- ProjectGraded
Detections in a SIEM
Each detection fires on its recorded attack and stays quiet on normal traffic.
- ProjectGraded
An alert queue, triaged
Your decisions match the answer key on true positives and every decision has a reason.
- ProjectGraded
A simulated attack
The timeline matches the simulation's ground truth on every key step.
- Every moduleGraded
6 graded checkpoints
Each module ends in work Nova grades line by line against a rubric you can read.
- AfterKept
Your hiring plan
Target roles, the gap map, the proof to send, weekly actions and an interview log.
The entries, not the grades: those are yours to earn. The page lives at /verify and an employer needs no account to open it.
5 entries, at your own pace. 25 spots are open.
Reserve my spotHow we help you find a job.
Proof, not a certificate: the projects you deployed are the thing you show, and the tools below are yours to use.
- 1
Your hiring plan
The same six-part plan the bootcamps use: target roles, the gap map, the proof to send, weekly actions, an interview log, the outcome. You run it with the career agent.
- 2
A record an employer can run
Your graded projects on /verify. An employer opens it and runs the code.
- 3
The career agent
Paste a real job posting at /career and it maps the role to your graded work and what to do next.
- 4
The roles directory
Every role we prepare people for, what it pays and what it asks, at /roles.
- 5
A path to the live cohort
If you want the instructor, the gates and the hiring sprint, the bootcamp on the same subject is one waitlist away.
Questions people ask.
About SOC Analyst Essentials, answered from the plan on this page.
Related programmes
- Cybersecurity Bootcamp · 12-week live bootcamp
- Cybersecurity Foundations · 14 h on demand
- AI for Cybersecurity · 8.5 h on demand
How long is SOC Analyst Essentials?
9.5 hours of recorded sessions across 7 modules, taken at your own pace. 6 of the modules end in work Nova grades.
Is SOC Analyst Essentials live or self-paced?
Self-paced. The sessions are recorded by an instructor who does this work, and Nova, Square 1's AI tutor, grades every checkpoint and project against a rubric you can read.
How much does SOC Analyst Essentials cost?
A$45 for the founding intake, paid once; the standard price is A$90. It is the same price in every country. Founding students keep their founding price on any second programme.
Who is SOC Analyst Essentials for?
People comfortable with computers and networks who want to work in a security operations centre: detecting, triaging and responding to real attacks. No security background needed. Before you start: Comfortable with computers and networks; no security background needed.
What will I build in SOC Analyst Essentials?
3 deployed projects: Detections in a SIEM, An alert queue, triaged and A simulated attack. Each is graded against a published rubric and kept on a record an employer can open at /verify.
What skills does SOC Analyst Essentials teach?
SIEM, log analysis, detection engineering, triage and incident response. It prepares you for roles such as SOC analyst, Security analyst and Incident responder (junior).
Does SOC Analyst Essentials guarantee a job?
No. No placement rate is published because there are no graduates to count yet. What you leave with is graded, deployed work on one record an employer can open and run, and a hiring plan you keep with the career agent.
How do I join SOC Analyst Essentials?
Reserve one of the twenty-five founding spots on this page with your email. Spot holders hear the opening date first, and nothing is charged before you confirm. The price on this page is in Australian dollars and is the same in every country.
25 spots. Hold one of them.
25 founding spots. Recorded by an instructor who does this work, graded by Nova. Spot holders hear the opening date first, and nothing is charged before you confirm.
- You can work a SOC shift: detect, triage and respond
- Three graded projects on your record
About a minute. No account, no card, and nothing is charged until you confirm.
