This is the working course for a security operations analyst. It teaches what the job actually involves: understanding the telemetry a SOC runs on, writing and tuning detections, triaging alerts under pressure, hunting for what the alerts missed, responding to incidents with a method, and reporting so that leadership acts. The topics align to the knowledge domains CySA+ covers, so it serves as preparation, but every lesson is built around the role rather than the exam. Each lesson ends with an action step that builds a home lab, a detection library or a portfolio artefact.
For help-desk and network staff moving into security, junior analysts formalising what they know, and anyone preparing for CySA+ who wants the practice behind the objectives.