// courses
Triage, response, hunting, and detection.
SOC analyst fundamentals
Tickets, triage, SIEM basics, and calm escalation — blue-team ops.
Incident response & DFIR
NIST-style IR plus evidence basics — contain without destroying proof.
Threat hunting
Hypothesis → data → find evil that alerts missed.
Detection engineering
Write, test, and tune detections without drowning the SOC.