Agent Foskett SOC Analyst Academy
This is the dedicated home for the Agent Foskett Security Operations Analyst learning path.
Across 100 scenario-driven lessons, analysts learn how to triage alerts, investigate incidents, follow evidence across Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra and cloud services, make defensible decisions, escalate correctly, contain threats and document what happened.
The specialist academies teach the technology. This academy teaches the job.

SOC Academy focus
Learn how an analyst thinks when the queue is full, the evidence is incomplete and a decision still has to be made.
SOC Analyst Academy learning paths
What makes this SOC Analyst Academy different?
Supporting Agent Foskett academies
Final thought
Agent Foskett SOC Analyst Academy
Agent Foskett SOC Analyst Academy is a 100-lesson Microsoft Security Operations learning path covering SOC alert triage, incident investigation, identity security, endpoint incidents, phishing, cloud and SaaS investigations, incident response, threat hunting and detection engineering.
Learn Microsoft Security Operations
Learn practical SOC analyst workflows using Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra, KQL, Defender for Endpoint, Defender for Cloud and Microsoft Security Copilot.
Scenario-driven SOC analyst training
The learning path uses realistic security incidents to teach prioritisation, evidence collection, investigation pivots, containment, escalation, handover and defensible conclusions.

