Tools guide

Cybersecurity tools for SOC analysts

What each category of security tool does, which products you will meet, and how to get hands-on practice for free.

Updated October 2026

You do not need to master every security product to get hired. Employers use different vendors, and the concepts transfer. What matters is understanding what each category of tool does, what questions it answers in an investigation, and having hands-on time with at least one tool in each category. Here are the categories SOC analysts use, with examples and free ways to practice.

SIEM (Security Information and Event Management)

The SIEM is the analyst’s main workspace: it collects logs from across the organization and lets you search, correlate and alert on them.

ToolNotes
Microsoft SentinelCloud SIEM using the KQL query language; common in Microsoft 365 organizations.
SplunkWidely used SIEM with its own SPL query language. Splunk offers free training and a free license tier for learning.
Elastic SecurityBuilt on the Elastic Stack; free self-managed options are popular in home labs.
WazuhOpen-source security platform combining SIEM and endpoint monitoring; good for home labs.

EDR and endpoint tools

Endpoint Detection and Response tools record what happens on laptops and servers so you can investigate processes, command lines and network connections, and isolate infected devices.

ToolNotes
Microsoft Defender for EndpointCommon enterprise EDR, closely integrated with Sentinel.
CrowdStrike Falcon, SentinelOneWidely deployed commercial EDR platforms.
SysmonFree Microsoft Sysinternals tool that adds detailed Windows logging — ideal for labs.
Sysinternals SuiteFree Windows utilities such as Process Explorer and Autoruns for investigating processes and persistence.

Network analysis

ToolNotes
WiresharkFree packet analyser; essential for understanding protocols and traffic.
tcpdumpCommand-line packet capture on Linux and macOS.
ZeekOpen-source network monitoring that turns traffic into rich logs.
SuricataOpen-source intrusion detection and prevention engine.
Security OnionFree Linux distribution bundling network and host monitoring tools for threat hunting and monitoring.

Threat intelligence and reputation

Analysts check indicators — IP addresses, domains, URLs and file hashes — against reputation sources many times a day.

ToolUse it for
VirusTotalFile hashes, URLs, domains and IPs checked against many security vendors.
AbuseIPDBCommunity reports on malicious IP addresses.
urlscan.ioSafely seeing what a URL loads and where it redirects.
AlienVault OTXCommunity threat intelligence and indicators.

Be careful what you upload. Files and URLs submitted to public services may be visible to others. Never upload confidential documents or internal data — check your organization’s policy first.

Analysis utilities and sandboxes

ToolUse it for
CyberChefDecoding and transforming data — Base64, URL encoding, hex and obfuscated PowerShell.
Email header analysersMaking long email headers readable during phishing investigations.
Malware sandboxes (e.g. ANY.RUN, Hybrid Analysis)Observing what a suspicious file or URL does in an isolated environment.

Case management

Every investigation needs a record. SOC teams use ticketing or case management tools — such as ServiceNow, Jira or the open-source TheHive — to track alerts, evidence, actions and handovers. Good notes in these systems are part of your job, not paperwork.

Where to start

  1. Learn Wireshark basics to understand traffic.
  2. Pick one SIEM and learn its query language (KQL or SPL).
  3. Install Sysmon in a Windows virtual machine and look at the events it generates.
  4. Use CyberChef and reputation services during practice investigations.
  5. Bring it together in a home SOC lab.

Tools are only useful when you know what question you are asking. Practice the investigation process in the SOC Analyst simulator and keep our cheat sheet close by.

Tools need a process

Learn the investigation process behind the tools.

Practice realistic SOC investigations from alert to report.

Start free. No experience required.