Technical Skills

Skills aligned with entry-level SOC analyst work.

These categories focus on practical defensive security knowledge, monitoring, investigation, and systems administration fundamentals.

Security Operations

  • Security monitoring
  • Alert investigation
  • Incident triage
  • Incident documentation
  • Escalation procedures

Identity & Access

  • Active Directory
  • Users and groups
  • Organizational Units
  • Group Policy Objects
  • Entra ID fundamentals

Systems

  • Windows Server
  • Windows client systems
  • Ubuntu Linux
  • File permissions
  • Service management

Networking

  • TCP/IP
  • DNS and DHCP
  • HTTP and HTTPS
  • Wireshark packet analysis
  • pfSense firewall fundamentals

Monitoring Tools

  • Splunk SIEM
  • Wazuh SIEM/XDR
  • Snort IDS/IPS
  • Log analysis
  • Threat hunting fundamentals

Assessment & Analysis

  • Nessus / Tenable
  • OpenVAS
  • VirusTotal
  • Joe Sandbox
  • MITRE ATT&CK and Cyber Kill Chain mapping