SECURITY OPERATIONS · MSP · MSSP

See the signal.
Make the call.
Defend the operation.

Build the knowledge analysts, SOC teams, MSPs, and MSSPs use to monitor environments, investigate what matters, respond with judgment, and deliver trustworthy security service.

SOC Analyst activity · availableOperational Paths · in developmentCredential · planned
Descend
THE OPERATION

Every capability strengthens the same defense.

Technology is centered on security operations and the supporting skills that help analysts, SOC teams, MSPs, and MSSPs see clearly, act responsibly, and deliver trustworthy service. These are current areas of study, with room to grow as the work changes.

Detection & Monitoring

Understand telemetry, detection logic, visibility gaps, and the difference between activity and meaningful signal.

Alert Triage

Set priority, test first explanations, identify risk, and decide where limited attention should go next.

Investigation & Forensics

Follow identity, endpoint, network, and cloud evidence without claiming more than the artifacts prove.

Incident Response

Contain harm, preserve evidence, coordinate decisions, and help an organization move from disruption to recovery.

Cloud, Identity & Endpoint

Work across the environments, access planes, devices, and controls that modern operations must defend together.

MSP / MSSP Service Delivery

Balance many customers, preserve context, build reliable handoffs, and make security work legible to the people it serves.

A cyan-lit security investigation chamber with evidence displays
OPERATIONAL JUDGMENT

From signal to a handoff another analyst can trust.

Tools surface activity. Analysts create meaning. Each Activity develops the reasoning between an alert and an action—and leaves work that can be inspected, questioned, and improved.

  1. SignalObserve before concluding.
  2. ContextTest competing explanations.
  3. DecisionChoose and defend the next action.
  4. HandoffMake the work usable by the next person.
LEARNING PATHS

Train toward the work—and the standards around it.

Paths begin with operational outcomes, then build the knowledge that supports role readiness and relevant certification study without promising a job, exam result, or title.

Available

SOC Analyst · Tier 1

Investigate risky sign-ins, distinguish observation from inference, make a defensible disposition, and produce an escalation-ready handoff.

Selected Activity
Available

Security Operations Foundations

Map telemetry, controls, identities, endpoints, networks, dependencies, and trust boundaries before deciding what an event means.

Selected Activity
In development

Detection, Triage & Investigation

Move from detection intent through alert validation, evidence pivots, case reasoning, and defensible closure or escalation.

Path sequence
Planned

MSP / MSSP Security Service Delivery

Build repeatable service workflows for multi-customer context, communication, prioritization, and operational continuity.

Path sequence
WORK THAT CAN BECOME EVIDENCE

Capability should be visible—not inferred from points or page views.

The long-term credential direction is built around reviewable work, a published performance standard, and a verification record. Today, the SOC Analyst credential remains a concept and is not issued.

Concept artwork for a future Mimir’s Well SOC Analyst Tier 1 credential
Credential identity concept · not issued
CREDENTIAL DIRECTION

Recognition must follow demonstrated work.

Before any credential becomes available, Mimir’s Well will publish its requirements, performance standard, reviewer process, versioning, appeals, expiration policy, and verification method.

Mimir’s Well does not currently issue the SOC Analyst certification shown here. These are concept artworks, not credentials. Completing an available Activity does not earn a certification, and the sample certificate identifiers and personal fields are nonfunctional.