TSOC School
Sign in
TrustNet analyst onboarding

Learn the SOC by working the SOC.

Ten self-paced days built from TrustNet's own historical tickets — search real logs, triage real alerts across four EDR vendors, and write the escalation a senior analyst would actually accept.

10
program days
40+
real-shaped tickets
4
EDR/XDR consoles
The program

Module 0, then ten graded days.

Every day ends in an artifact your manager can grade — a verdict, a query, a written escalation.

00
Module 0 — Tool Literacy

EDR/XDR, SIEM, Mail Relay, Identity & Cloud — four field guides, five questions each.

01
Day 1 — Ticket Triage

Read five real-shaped tickets. Call the verdict.

02
Day 2 — Log Literacy

Search a raw log console yourself and prove what happened.

03
Day 3 — Query Day

Write real queries against a live console and translate them across SIEMs.

04
Day 4 — Phishing

Look up every IOC yourself before you call a verdict.

05
Day 5 — Endpoint & EDR

CrowdStrike, SentinelOne, Trend Micro, Defender — pick the right console.

06
Day 6 — Identity & Cloud

Search the sign-in console before you trust any single login.

07
Day 7 — Network & Lateral Movement

Reconstruct a full intrusion path from beacon to domain controller.

08
Day 8 — Writing & Escalation

Write the escalation a senior would accept with no follow-up questions.

09
Day 9 — Tuning & Detection

Decide what to tune, and map alerts to MITRE ATT&CK.

10
Day 10 — Capstone

One intrusion, four stages, one final report.