Course Syllabus: SOC Fundamentals

Module 0: Primer and Philosophy Behind This Course

This primer isn’t required, but it explains my thoughts in writing this course and contains a mock syllabus mapping (16-week and 8-week tracks). My thoughts on GenAI and how I used it to develop this content are also included.

Module 1: Introduction to the SOC

What a Security Operations Center actually does once you strip away Hollywood tropes and vendor hype. Covers the organizational emergence of a SOC, physical/logical architectures, staffing hierarchies (Tier 1–3, Engineers, Architects, Managers, CISO), and operational responsibilities (MITRE ATT&CK/D3FEND, reactive triage, threat hunting, and compliance).

Module 2: Endpoint Defense

Protecting laptops, workstations, and servers when the traditional corporate perimeter dissolves. Covers CIS Controls 1 & 2 baseline management across Windows, macOS, and Linux (eBPF), EDR, Attack Surface Reduction, privilege management, and CISA KEV vulnerability patching.

Module 3: Mobile Defense

Navigating the BYOD wild west where personal privacy meets corporate risk. Covers OS containerization, mobile posture checks, and service-level access controls.

Module 4: Network Defense

While not strictly true, all things cross the wire and the wire never lies. Stuxnet is an obvious exception, but review the OSI Layers 1 through 4, PKI certificates, and touch on packet analysis.

Module 5: Tooling

Deconstructing the “single pane of glass” myth and looking at the logging ouroboros. Examines log storage economics, schemas, detection engineering, telemetry pipelines, SOAR, threat intelligence, ITSM case management, and Open-Source vs. Commercial TCO.

Discussion