Detection & Monitoring
Understand telemetry, detection logic, visibility gaps, and the difference between activity and meaningful signal.
Build the knowledge analysts, SOC teams, MSPs, and MSSPs use to monitor environments, investigate what matters, respond with judgment, and deliver trustworthy security service.
Technology is centered on security operations and the supporting skills that help analysts, SOC teams, MSPs, and MSSPs see clearly, act responsibly, and deliver trustworthy service. These are current areas of study, with room to grow as the work changes.
Understand telemetry, detection logic, visibility gaps, and the difference between activity and meaningful signal.
Set priority, test first explanations, identify risk, and decide where limited attention should go next.
Follow identity, endpoint, network, and cloud evidence without claiming more than the artifacts prove.
Contain harm, preserve evidence, coordinate decisions, and help an organization move from disruption to recovery.
Work across the environments, access planes, devices, and controls that modern operations must defend together.
Balance many customers, preserve context, build reliable handoffs, and make security work legible to the people it serves.

Tools surface activity. Analysts create meaning. Each Activity develops the reasoning between an alert and an action—and leaves work that can be inspected, questioned, and improved.
Paths begin with operational outcomes, then build the knowledge that supports role readiness and relevant certification study without promising a job, exam result, or title.
Investigate risky sign-ins, distinguish observation from inference, make a defensible disposition, and produce an escalation-ready handoff.
Map telemetry, controls, identities, endpoints, networks, dependencies, and trust boundaries before deciding what an event means.
Move from detection intent through alert validation, evidence pivots, case reasoning, and defensible closure or escalation.
Build repeatable service workflows for multi-customer context, communication, prioritization, and operational continuity.
The long-term credential direction is built around reviewable work, a published performance standard, and a verification record. Today, the SOC Analyst credential remains a concept and is not issued.

Before any credential becomes available, Mimir’s Well will publish its requirements, performance standard, reviewer process, versioning, appeals, expiration policy, and verification method.

