Back to Companion Guides
Study Material
Reader Study Guide
Solidify your understanding chapter by chapter. Each section focuses on how analysts think, speak, and decide — not just what they do.
This will open your print dialog. Print as usual, or select "Save as PDF" to download.
First SOC Shift — Reader Study Guide
By Chapter • First SOC Shift Companion Guide
Chapter 1
First Alert in the Queue
Core Focus
- Understanding what alerts are (and are not)
- Learning how triage works in practice
- Getting comfortable with uncertainty
Key Takeaways
- Most alerts are not incidents
- Triage is about prioritization, not fixing
- Asking questions is part of the job
Language to Be Comfortable With
Alert vs eventAlert queueTriageFalse positive vs true positiveTicket / case
Self-Check
- • Can you explain why an alert might not be a problem?
- • Can you describe triage without using technical jargon?
Chapter 2
When the Noise Isn't Noise
Core Focus
- Recognizing patterns across many small signals
- Understanding alert fatigue
- Detecting subtle authentication attacks
Key Takeaways
- Noise becomes dangerous when patterns are missed
- Volume can hide real risk
- Correlation matters more than single alerts
Language to Be Comfortable With
Alert fatigueAuthentication logsPassword sprayingCorrelation ruleTime window
Self-Check
- • Can you explain why password spraying is hard to detect?
- • Can you describe alert fatigue in your own words?
Chapter 3
A Ticket That Wouldn't Close
Core Focus
- How incidents evolve over time
- Malware response basics
- Containment vs eradication
Key Takeaways
- Tickets stay open when risk remains
- Containment is not resolution
- User statements are data, not truth
Language to Be Comfortable With
MalwareIndicator of Compromise (IOC)Endpoint logsHost isolationContainment vs eradication
Self-Check
- • Can you explain the difference between containment and resolution?
- • Why might a ticket stay open after initial response?
Chapter 4
The Cloud Misstep
Core Focus
- Risk without an attacker
- Misconfiguration as a security issue
- Thinking in terms of exposure
Key Takeaways
- "Nothing happened" does not mean "no risk"
- Data sensitivity drives impact
- Logs help confirm absence, not certainty
Language to Be Comfortable With
IAMData classificationAudit logRisk assessmentCompensating control
Self-Check
- • Can you explain why exposure alone matters?
- • Can you describe risk without referencing a breach?
Chapter 5
Inside the Perimeter
Core Focus
- Internal visibility
- Lateral movement
- Threat hunting mindset
Key Takeaways
- Internal activity can be more dangerous than external noise
- Trust boundaries matter
- Proactive searching is part of defense
Language to Be Comfortable With
Lateral movementPrivilege escalationNetwork segmentVLANThreat hunting
Self-Check
- • Can you explain why internal traffic raises concern?
- • Can you describe segmentation in plain language?
Chapter 6
Evidence Matters
Core Focus
- Investigation discipline
- Evidence preservation
- Slowing down when stakes are high
Key Takeaways
- Speed can destroy evidence
- Documentation protects credibility
- Understanding root cause prevents recurrence
Language to Be Comfortable With
DFIRChain of custodyForensic imageMemory dumpTimeline analysis
Self-Check
- • Can you explain why reimaging is sometimes delayed?
- • Can you describe DFIR without mentioning tools?
Chapter 7
Lessons Logged
Core Focus
- Post-incident review
- Improvement over blame
- Playbook refinement
Key Takeaways
- Incidents teach if teams learn
- Blame culture blocks growth
- Improvement requires honesty
Language to Be Comfortable With
Post-incident reviewLessons learnedPlaybookSOPDetection gap
Self-Check
- • Can you explain why post-incident reviews exist?
- • Can you describe how detection rules get updated?
Chapter 8
The Handover
Core Focus
- Shift continuity
- Operational communication
- Transition of ownership
Key Takeaways
- Dropped context creates risk
- Clear handover protects people and process
- Good communication is non-negotiable
Language to Be Comfortable With
Shift handoverOn-callRun bookChange windowMonitoring priority
Self-Check
- • Can you explain why handovers matter?
- • Can you describe a good handover in your own words?