Learn the SOC by working the SOC.
Ten self-paced days built from TrustNet's own historical tickets — search real logs, triage real alerts across four EDR vendors, and write the escalation a senior analyst would actually accept.
Module 0, then ten graded days.
Every day ends in an artifact your manager can grade — a verdict, a query, a written escalation.
EDR/XDR, SIEM, Mail Relay, Identity & Cloud — four field guides, five questions each.
Read five real-shaped tickets. Call the verdict.
Search a raw log console yourself and prove what happened.
Write real queries against a live console and translate them across SIEMs.
Look up every IOC yourself before you call a verdict.
CrowdStrike, SentinelOne, Trend Micro, Defender — pick the right console.
Search the sign-in console before you trust any single login.
Reconstruct a full intrusion path from beacon to domain controller.
Write the escalation a senior would accept with no follow-up questions.
Decide what to tune, and map alerts to MITRE ATT&CK.
One intrusion, four stages, one final report.