PPS CLASS · START HERE
Welcome to the SOC Analyst Projects.
Here's what a SOC actually is, what it pays, and how long this track takes. All 10 projects are right below, starting with Project 1.
WHAT IS A SOC?
Where cybersecurity actually happens, day to day
A SOC, short for Security Operations Center, is the team that watches an organization's systems around the clock for signs of an attack. Analysts sit in front of dashboards fed by firewalls, endpoints, and cloud logs, and their job is simple to describe and hard to do well: notice something wrong, figure out what it actually is, and decide what happens next.
Tier 1 is the entry point into that world. You're the first set of eyes on an alert, the one who decides whether it's noise or something a senior analyst needs to see right now. Every project in this track is built to get you ready for exactly that seat.
A security operations team monitoring live alerts. Photo via Pexels
What the role actually pays
Pay depends on experience, location, and whether you're doing pure Tier 1 work or something broader. Here's the real spread, pulled from the sites employers and analysts actually use to benchmark this role.
A realistic timeline, not a sprint
Most people work through all 10 projects in about 6 to 10 weeks, putting in a few hours a week alongside a job or Security+ study. Move faster if you already have some hands-on experience, slower if you don't, both are fine. Nothing here is timed. Finish Project 1 well before you worry about Project 10.
Start with Project 1. Each one builds on the last, in order.
Home SOC Lab Build
Build your own detection environment before touching real alerts. It's the sandbox every later project in this track runs inside.
Alert Triage & Shift Monitoring
Watch a live SIEM/EDR queue, do the first-pass read on each alert, and decide what actually needs escalation.
Phishing Mail Investigation
Pull apart headers, links, and attachments on a suspicious email and trace it from inbox to root cause.
Escalation & Incident Documentation
Write the ticket a Tier 2 analyst can act on without redoing your work. It's the most graded, least glamorous Tier 1 skill.
Account Takeover Investigation
Chase an impossible-travel login or MFA bypass back through the identity logs to confirm compromise.
Log & SIEM Correlation
Build detection rules that actually catch brute-force attempts and PowerShell abuse in real log data.
Threat Intel & IOC Enrichment
Take an indicator from a real investigation and turn it into a short, usable threat brief.
Endpoint Monitoring
Catch credential dumping, persistence, and processes launching from temp folders before they spread.
Network Traffic & IDS Analysis
Correlate IDS alerts against raw packet captures and map the traffic to real attacker techniques.
Malware Triage in a Sandbox
Detonate a suspicious file safely, pull the IOCs, and document it the way you'd hand it to Tier 2.