Security Operations Series
SOC Analyst Interview Kit
Organised like an interview rather than like a syllabus: the questions, the frameworks for answering them, the scenarios behind them, and a rubric to practise against.
What's in it
- Around 160 pages across 10 chapters.
- 200+ flashcards, with answer frameworks rather than fixed answers — interviewers rephrase, and a memorised answer does not survive that.
- 25 scenario walkthroughs: account lockout, suspicious PowerShell, lateral movement, and the rest of the Tier 1 queue.
- Splunk SPL and Microsoft Sentinel KQL exercises.
- MITRE ATT&CK coverage tied to the scenarios.
- Behavioural frameworks — including how to answer "tell me about a time you missed an alert" without sandbagging yourself.
- A mock-interview rubric you can run with a friend or alone.
What it is not
- Not a certification course. It will not prepare you for Security+ or CySA+, and it does not try to.
- Not a lab build. If you want the environment to practise in, that is the Proxmox line.
- Not video. It is a written guide you work through.
- Not the only resource worth using. TryHackMe goes deeper on hands-on, Splunk's own training is free, and the Wazuh docs are good. This is the interview-shaped one.
Why trust it
It was written from a working three-node Proxmox cluster running Wazuh with custom Sigma rules — the same alert workflow a Tier 1 analyst sees — not from a syllabus. The infrastructure behind the security material is public and inspectable.
If you want the lab too
Homelab + SOC Career Pack pairs this kit with the flagship Proxmox build guide, for people doing both the interview prep and the environment behind it.
Not ready to buy
Start with the free sheet.
SOC Interview Cheat Sheet is the reference layer from this kit, given away on its own. If it is useful, the kit is the system underneath it. If it is not, you have lost nothing.