CyberPath Sim

Blue Team Path

Lesson 1 — What a SOC analyst does

Learn the basic job of a SOC analyst, how alerts are handled, what evidence matters, and how analysts decide whether activity is benign, suspicious, or malicious.

Lesson

SOC fundamentals

A SOC analyst monitors alerts, reviews logs, investigates unusual behavior, and determines whether the activity is safe, suspicious, or malicious.

Analysts usually begin with alert context, then look at supporting evidence like authentication logs, host activity, user context, asset value, and network behavior.

Their job is not just to "find bad stuff." It is to make fast, accurate decisions, reduce false positives, escalate real incidents, and document what happened clearly.

A strong SOC analyst asks:

  • What triggered this alert?
  • What evidence supports it?
  • What asset or user is involved?
  • What is the immediate risk?
  • What action should happen next?

Video block

Lesson Video Placeholder

Add your YouTube embed or MP4 lesson here later.

Checkpoint Questions

Check your understanding


End Quiz

Pass to unlock the room