Skip to content

Courses / On-demand courses

On demandRecorded by an instructor, graded by Nova

SOC Analyst Essentials

Detect, triage and respond to real attacks the way a security operations centre does.

SOC Analyst Essentials is a self-paced online course: 9.5 hours of recorded sessions across 7 modules, with 6 graded by Nova, Square 1's AI tutor. The founding price is A$45, down from A$90. Start any time and keep your own pace.

Price: A$45A$9050% off

Founding price for the first cohort, until 21 October.

Founding price, one payment. Founding students keep their founding price on any second programme.

Founding intake

Spot holders hear the start date first.

Reserve your spot

Three fields hold it. A few short questions after that.

No account, no card. Holding a spot is free, and you confirm before anything is charged. We use these details to place you, never to sell.

Get the course booklet

SOC Analyst Essentials. PDF, 11 pages, 256 KB. Tell us who you are and it downloads straight away.

You are a

No account, no card. We email you a copy and may contact you about this course. We never sell your details. Privacy

Module by module

  1. Module 1 · 60 min

    Inside a SOC: alerts, tiers and shifts

  2. Module 2 · 90 min · graded

    Logs that matter: endpoints, network, cloud

  3. Module 3 · 90 min · graded

    SIEM searches and detections

  4. Module 4 · 60 min · graded

    Triage: true, false or not sure

  5. Module 5 · 90 min · graded

    Incident response from first alert to close

  6. Module 6 · 60 min · graded

    AI in the SOC

  7. Module 7 · 120 min · graded

    Project: a simulated attack, detected and handled

recorded hours
9.5
modules, in order
7
deployed projects
3
graded checkpoints
6

Who it is for, and what you receive.

People comfortable with computers and networks who want to work in a security operations centre: detecting, triaging and responding to real attacks. No security background needed.

Before you start

Comfortable with computers and networks; no security background needed.

Skills

  • SIEM
  • log analysis
  • detection engineering
  • triage
  • incident response
  1. 1

    The recorded sessions

    Taught by an instructor, taken in order at your own pace, yours for twelve months.

  2. 2

    Graded work after every module

    Exercises and projects marked by Nova against a rubric you can read, with what you did well and what to fix.

  3. 3

    The projects

    Deployed and graded, each one on your record with its repository.

  4. 4

    Your hiring plan

    The same six-part plan the bootcamps use, run with the career agent.

  5. 5

    The record and the certificate

    Every grade at square1ai.com/u/{handle}; a credential ID that resolves at square1ai.com/verify.

  6. 6

    Nova as your tutor

    Help that is about your actual work, because it has read all of it.

The content plan, module by module.

9.5 recorded hours from an instructor, taken in order at your own pace. Nova grades the work at the end of each module.

  1. Inside a SOC: alerts, tiers and shifts

    Module 1 · 60 min

    Watch and take notes; nothing to submit in this module.

    • Python
    • Azure
    • AWS

    What a SOC does

    Tiers and escalation

    Shift handovers

  2. Logs that matter: endpoints, network, cloud

    Module 2 · 90 min

    Graded at the end: A log source onboarded and parsed.

    • Python
    • Azure
    • AWS

    Windows and Linux logs

    Network logs

    Cloud audit logs

  3. SIEM searches and detections

    Module 3 · 90 min

    Graded at the end: Three detections written and tested.

    • Python
    • Azure
    • AWS

    Search languages

    Writing a detection

    Testing against known attacks

  4. Triage: true, false or not sure

    Module 4 · 60 min

    Graded at the end: Twenty alerts triaged with reasons.

    • Python
    • Azure
    • AWS

    Context and enrichment

    False-positive patterns

    Writing up the decision

  5. Incident response from first alert to close

    Module 5 · 90 min

    Graded at the end: An incident handled with a timeline.

    • Python
    • Azure
    • AWS

    Containment

    Eradication and recovery

    The timeline and report

  6. AI in the SOC

    Module 6 · 60 min

    Graded at the end: An AI-assisted triage you checked by hand.

    • Python
    • Azure
    • AWS

    Summarising alerts

    Checking the assistant

    What not to hand over

  7. Project: a simulated attack, detected and handled

    Module 7 · 120 min

    Graded at the end: The detections, the timeline and the incident report.

    • Python
    • Azure
    • AWS

    The attack

    Detection

    Response

    The report

The projects.

Each is deployed and graded by Nova against a rubric you can read before you start.

  1. 1

    Detections in a SIEM

    Onboard endpoint and network logs into a free SIEM, then write three detections for common attacks and test each against a recorded attack.

    You hand in

    • Log onboarding notes
    • Three detection rules
    • Test evidence for each

    The rubric requires

    Each detection fires on its recorded attack and stays quiet on normal traffic.

  2. 2

    An alert queue, triaged

    Work a queue of twenty realistic alerts, decide true, false or uncertain for each, and write the reason and next step a teammate on the next shift could act on.

    You hand in

    • Triage log
    • Escalation notes
    • Shift handover

    The rubric requires

    Your decisions match the answer key on true positives and every decision has a reason.

  3. 3

    A simulated attack

    A simulated intrusion runs in a lab environment. Detect it, contain it, build the timeline from the logs and write the incident report for a manager and for engineers.

    You hand in

    • Detection evidence
    • Incident timeline
    • Incident report
    • Lessons learned

    The rubric requires

    The timeline matches the simulation's ground truth on every key step.

What you can do at the end.

Detections, triage and an incident you handled end to end, and three graded projects on your record that show it.

  1. 1

    Explain how a SOC works: alerts, tiers, shifts and handovers.

  2. 2

    Onboard and read the log sources that matter for detection.

  3. 3

    Write and test SIEM detections for common attacks.

  4. 4

    Triage alerts as true, false or uncertain, with reasons.

  5. 5

    Handle an incident from first alert to close with a timeline.

  6. 6

    Use AI to speed up triage and check its work by hand.

Roles this prepares you for

  • SOC analyst
  • Security analyst
  • Incident responder (junior)

No placement rate is shown, because there are no graduates to count yet. The roles above are what the projects are built for.

Your record at the end.

Every exercise and project is graded by Nova against a rubric you can read, and every grade is kept on one page an employer can open and run. This is what the programme writes to it.

Graded, line by line
Nova reads every submission against the brief and the rubric and returns a score, what you did well and what to fix.
Module by module
Each module ends in graded work; the next opens when you are ready, on your own schedule.
Nova remembers
Help is about your actual work, because the tutor has every submission and every failed exercise of yours.
One page an employer can run
Every grade and project at /verify. An employer opens it and runs the code.

Record, SOC Analyst Essentials

Example

  1. Project

    Detections in a SIEM

    Each detection fires on its recorded attack and stays quiet on normal traffic.

    Graded
  2. Project

    An alert queue, triaged

    Your decisions match the answer key on true positives and every decision has a reason.

    Graded
  3. Project

    A simulated attack

    The timeline matches the simulation's ground truth on every key step.

    Graded
  4. Every module

    6 graded checkpoints

    Each module ends in work Nova grades line by line against a rubric you can read.

    Graded
  1. After

    Your hiring plan

    Target roles, the gap map, the proof to send, weekly actions and an interview log.

    Kept

The entries, not the grades: those are yours to earn. The page lives at /verify and an employer needs no account to open it.

5 entries, at your own pace. 25 spots are open.

Reserve my spot

How we help you find a job.

Proof, not a certificate: the projects you deployed are the thing you show, and the tools below are yours to use.

  1. 1

    Your hiring plan

    The same six-part plan the bootcamps use: target roles, the gap map, the proof to send, weekly actions, an interview log, the outcome. You run it with the career agent.

  2. 2

    A record an employer can run

    Your graded projects on /verify. An employer opens it and runs the code.

  3. 3

    The career agent

    Paste a real job posting at /career and it maps the role to your graded work and what to do next.

  4. 4

    The roles directory

    Every role we prepare people for, what it pays and what it asks, at /roles.

  5. 5

    A path to the live cohort

    If you want the instructor, the gates and the hiring sprint, the bootcamp on the same subject is one waitlist away.

Get the course booklet

SOC Analyst Essentials. PDF, 11 pages, 256 KB. Tell us who you are and it downloads straight away.

You are a

No account, no card. We email you a copy and may contact you about this course. We never sell your details. Privacy

Questions people ask.

About SOC Analyst Essentials, answered from the plan on this page.

Related programmes

How long is SOC Analyst Essentials?

9.5 hours of recorded sessions across 7 modules, taken at your own pace. 6 of the modules end in work Nova grades.

Is SOC Analyst Essentials live or self-paced?

Self-paced. The sessions are recorded by an instructor who does this work, and Nova, Square 1's AI tutor, grades every checkpoint and project against a rubric you can read.

How much does SOC Analyst Essentials cost?

A$45 for the founding intake, paid once; the standard price is A$90. It is the same price in every country. Founding students keep their founding price on any second programme.

Who is SOC Analyst Essentials for?

People comfortable with computers and networks who want to work in a security operations centre: detecting, triaging and responding to real attacks. No security background needed. Before you start: Comfortable with computers and networks; no security background needed.

What will I build in SOC Analyst Essentials?

3 deployed projects: Detections in a SIEM, An alert queue, triaged and A simulated attack. Each is graded against a published rubric and kept on a record an employer can open at /verify.

What skills does SOC Analyst Essentials teach?

SIEM, log analysis, detection engineering, triage and incident response. It prepares you for roles such as SOC analyst, Security analyst and Incident responder (junior).

Does SOC Analyst Essentials guarantee a job?

No. No placement rate is published because there are no graduates to count yet. What you leave with is graded, deployed work on one record an employer can open and run, and a hiring plan you keep with the career agent.

How do I join SOC Analyst Essentials?

Reserve one of the twenty-five founding spots on this page with your email. Spot holders hear the opening date first, and nothing is charged before you confirm. The price on this page is in Australian dollars and is the same in every country.

25 spots. Hold one of them.

25 founding spots. Recorded by an instructor who does this work, graded by Nova. Spot holders hear the opening date first, and nothing is charged before you confirm.

  • You can work a SOC shift: detect, triage and respond
  • Three graded projects on your record
Reserve my spot

About a minute. No account, no card, and nothing is charged until you confirm.