Cybersecurity 路 Free

SOC Analyst Level 1 with Splunk

Train for a Level 1 SOC analyst role: what the job is really like, the incident response process, the Windows event IDs you read every shift, Splunk search and SPL, hunting through Boss of the SOC v1, Wireshark traffic analysis, phishing email analysis, and MITRE ATT&CK with free threat intelligence.

9 modules 4h 47m of video English 路 self-paced

Inside the course

SOC Analyst Level 1 with Splunk: Syllabus at a glanceSOC Analyst Level 1 with Splunk: What you will be able to doSOC Analyst Level 1 with Splunk: Tools and credits

From the lessons

  • A Real Day in Life of a SOC Analyst | Remote Work from Home Reality

    What a SOC analyst actually does

    Tech with Jono

  • CertMike Explains Incident Response Process

    The incident response process

    Mike Chapple

  • Windows Logon Events 4624, 4625, 4634 Explained

    Windows event logs every analyst must read

    Infosec Wizard

  • Basic Searching in Splunk Enterprise

    Splunk search basics and SPL

    Splunk How-To

  • Splunk Threat Hunting - Boss of the SOC V1 - Cyber Defenders = Q's 1-32

    Hunting in Splunk: Boss of the SOC

    Hoplite Security

  • Cybersecurity Tool for SOC Analyst: Wireshark

    Network traffic with Wireshark

    MyDFIR

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Describe the SOC analyst's job, tools and metrics; follow the incident response process from triage to lessons learned; read Windows logon, account and process events and spot a brute-force-to-persistence sequence; write SPL searches that count, filter and chart; hunt through the Boss of the SOC v1 dataset from a hypothesis; analyse suspicious traffic in Wireshark; analyse a phishing email from its headers, links and attachments; and map an incident to MITRE ATT&CK and check indicators against threat intelligence.

  • Describe the SOC analyst's job, tools, verdicts and metrics
  • Follow the incident response process and contain without losing evidence
  • Read Windows logon, account and process event IDs
  • Write SPL searches that filter, count and chart
  • Hunt through Boss of the SOC v1 from a hypothesis
  • Analyse suspicious traffic in Wireshark
  • Analyse phishing emails from headers, links and attachments
  • Map incidents to MITRE ATT&CK and use free threat intelligence

For you

Taking SOC Analyst Level 1 with Splunk from the United States

The course project 路 about 10 hours

Level 1 investigation of an overnight RDP intrusion at a lender: triage playbook, IOC register, incident report and gap register

Investigate an overnight alert as a Level 1 SOC analyst at a lending company that runs Splunk: triage the brute-force alert, trace what the attacker did from the Windows events, record the indicators, map the incident to MITRE ATT&CK, and write it up so Tier 2 and management can act. The sample pack shows each document for a consumer lender in Leeds, England.

Sample document pack, 4 documents, filled in for the scenario

  • ProcedureTriage playbook: failed-logon spike and brute force
  • RegisterIndicator register: JUMP01 intrusion
  • ReportIncident report: RDP intrusion on JUMP01
  • Risk registerDetection gap register after the JUMP01 incident

Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.

Course content

9 modules 路 21 lessons 路 4h 47m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.

  1. 01What a SOC analyst actually does20m
  2. 02The incident response process31m
  3. 03Windows event logs every analyst must read29m
  4. 04Splunk search basics and SPL36m
  5. 05Hunting in Splunk: Boss of the SOC1h 5m
  6. 06Network traffic with Wireshark39m
  7. 07Phishing email analysis32m
  8. 08MITRE ATT&CK and threat intelligence29m

Requirements

Who it is for
Beginner, with the basics in place. You should know what an IP address, a port and the CIA triad are; Cybersecurity Fundamentals covers them if not.
Software
Splunk Enterprise (the free 60-day trial, which can convert to the free licence), the public Boss of the SOC v1 dataset, Wireshark, and a Windows virtual machine for Event Viewer. All free. What to download, and how
Hardware
A laptop or desktop with 16 GB of RAM is comfortable for Splunk and a Windows VM together; 8 GB works if you run them one at a time.

Software you need

What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.

The Windows virtual machine is for the Event Viewer exercises.

Required

  1. 01

    Splunk Enterprise

    Splunk (a Cisco company)

    Free trial: 60 days, then a free licence
    Runs on
    Windows 10 and Windows Server 2019, 2022, 2025; Linux (kernel 4.x, 5.x, 6.x; .rpm, .deb, .tgz); macOS on Apple silicon
    Account
    A free splunk.com account

    The Enterprise trial lasts 60 days and indexes up to 500 MB a day, with no credit card. You can then switch to Splunk Free, which keeps 500 MB a day with no time limit but has no alerting, no user logins and no clustering.

  2. 02

    Boss of the SOC (BOTS) Dataset Version 1

    Splunk

    Free
    Runs on
    Any system that runs Splunk Enterprise
    Account
    None needed
    Size
    About 6.1 GB compressed (Splunk pre-indexed); about 135 MB for the attack-only version

    The dataset is released to the public domain under CC0, so you can use it freely. Splunk and the add-ons it needs are licensed separately.

  3. 03

    Wireshark

    Wireshark Foundation

    Free
    Runs on
    Windows 11 or 10 64-bit (x64 or Arm64), Windows Server 2016 or later, macOS (Universal disk image), Linux
    Account
    None needed

    Free, open source software. No licence fee for any use.

  4. 04

    Oracle VirtualBox

    Oracle

    Free
    Runs on
    Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
    Account
    None needed

    The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.

  5. 05

    Windows 11 Enterprise (evaluation)

    Microsoft

    Free trial: 90 days
    Runs on
    Installs as a virtual machine or on a PC; ISO for x64 and Arm64
    Account
    A short registration form on the Microsoft Evaluation Center

    A full-featured 90-day evaluation for testing, with no product key needed. When it expires the desktop turns black, a notice stays on screen and the PC shuts down every hour.

Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.

SOC Analyst Level 1 with Splunk at a glance

SOC Analyst Level 1 with Splunk is a free, self-paced online course from EDWartens for aspiring SOC analysts, IT support staff and security students. It has 9 modules and 4h 47m of video lessons by MyDFIR, ZeroDayVault (Cyber Panchayat), Cyber Shield and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.

All course facts
Price
Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
Who it is for
Aspiring SOC analysts, IT support staff and security students
Format
9 self-paced modules, 4h 47m of video, written notes, a practice task per module and one final assessment.
Level
Beginner. Beginner, with the basics in place. You should know what an IP address, a port and the CIA triad are; Cybersecurity Fundamentals covers them if not.
Brand
Vendor-neutral
Software
Splunk Enterprise (the free 60-day trial, which can convert to the free licence), the public Boss of the SOC v1 dataset, Wireshark, and a Windows virtual machine for Event Viewer. All free.
Hardware
A laptop or desktop with 16 GB of RAM is comfortable for Splunk and a Windows VM together; 8 GB works if you run them one at a time.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
MyDFIR, ZeroDayVault (Cyber Panchayat), Cyber Shield, CyberPlatter (independent creators, credited below)
Language
English
Last updated
27 September 2026

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

Pairs well with

More free courses: Free cyber security courses 路 Free IT security and SOC analyst courses

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of SOC Analyst Level 1 with Splunk, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

Do I need to know cybersecurity already?

You need the basics: IP addresses, ports, what a log is and the CIA triad. If those are new, take Cybersecurity Fundamentals first, then this course.

Is this a Splunk certification course?

No. It teaches the Splunk search skills a Level 1 analyst uses and is not affiliated with Splunk. It is not preparation for a specific Splunk exam, and the EDWartens certificate is not a Splunk certification.

Do I have to pay for Splunk?

No. The Splunk Enterprise trial is free for 60 days and can then be converted to Splunk's free licence, which allows 500 MB of data a day on a single instance. That is plenty for the labs and the BOTSv1 dataset.

Can I do the labs on a work laptop?

Use your own machine or a personal virtual machine. Practice captures and phishing samples can contain live malware, and some organisations do not allow security tools on their devices.

Is the SOC Analyst Level 1 with Splunk course really free?

Yes. Every module, the notes, the project and the final assessment. The only paid item is the certificate, if you want it.

What certificate does the SOC Analyst Level 1 with Splunk course give?

An EDWartens Certificate of Completion, issued when you pass the final assessment, with a number anyone can verify on our site.

How long does the SOC Analyst Level 1 with Splunk course take?

About 7.7 hours of video lessons, notes and practice questions, plus about 10 hours if you do the project. At an hour a day, that is about two and a half weeks.

What is the project in the SOC Analyst Level 1 with Splunk course?

You investigate an overnight RDP intrusion at a lending company as the Level 1 analyst on shift. You reproduce the events in your own lab, trace them with SPL, and write a triage playbook, an indicator register, an incident report with an ATT&CK mapping, and a detection gap register.

What you walk away with

Your certificate for SOC Analyst Level 1 with Splunk

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for SOC Analyst Level 1 with Splunk
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

  • Adds to LinkedIn in one click

  • QR code on the certificate

  • Names what you can do

  • A permanent link

  • Earned, not attended

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, US$23.99, with a receipt.

Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.