Module 0: Primer and Philosophy Behind This Course
This primer isn’t required, but it explains my thoughts in writing this course and contains a mock syllabus mapping (16-week and 8-week tracks). My thoughts on GenAI and how I used it to develop this content are also included.
Module 1: Introduction to the SOC
What a Security Operations Center actually does once you strip away Hollywood tropes and vendor hype. Covers the organizational emergence of a SOC, physical/logical architectures, staffing hierarchies (Tier 1–3, Engineers, Architects, Managers, CISO), and operational responsibilities (MITRE ATT&CK/D3FEND, reactive triage, threat hunting, and compliance).
Module 2: Endpoint Defense
Protecting laptops, workstations, and servers when the traditional corporate perimeter dissolves. Covers CIS Controls 1 & 2 baseline management across Windows, macOS, and Linux (eBPF), EDR, Attack Surface Reduction, privilege management, and CISA KEV vulnerability patching.
Module 3: Mobile Defense
Navigating the BYOD wild west where personal privacy meets corporate risk. Covers OS containerization, mobile posture checks, and service-level access controls.
Module 4: Network Defense
While not strictly true, all things cross the wire and the wire never lies. Stuxnet is an obvious exception, but review the OSI Layers 1 through 4, PKI certificates, and touch on packet analysis.
Module 5: Tooling
Deconstructing the “single pane of glass” myth and looking at the logging ouroboros. Examines log storage economics, schemas, detection engineering, telemetry pipelines, SOAR, threat intelligence, ITSM case management, and Open-Source vs. Commercial TCO.