Tools guide
What each category of security tool does, which products you will meet, and how to get hands-on practice for free.
Updated October 2026
You do not need to master every security product to get hired. Employers use different vendors, and the concepts transfer. What matters is understanding what each category of tool does, what questions it answers in an investigation, and having hands-on time with at least one tool in each category. Here are the categories SOC analysts use, with examples and free ways to practice.
The SIEM is the analyst’s main workspace: it collects logs from across the organization and lets you search, correlate and alert on them.
| Tool | Notes |
|---|---|
| Microsoft Sentinel | Cloud SIEM using the KQL query language; common in Microsoft 365 organizations. |
| Splunk | Widely used SIEM with its own SPL query language. Splunk offers free training and a free license tier for learning. |
| Elastic Security | Built on the Elastic Stack; free self-managed options are popular in home labs. |
| Wazuh | Open-source security platform combining SIEM and endpoint monitoring; good for home labs. |
Endpoint Detection and Response tools record what happens on laptops and servers so you can investigate processes, command lines and network connections, and isolate infected devices.
| Tool | Notes |
|---|---|
| Microsoft Defender for Endpoint | Common enterprise EDR, closely integrated with Sentinel. |
| CrowdStrike Falcon, SentinelOne | Widely deployed commercial EDR platforms. |
| Sysmon | Free Microsoft Sysinternals tool that adds detailed Windows logging — ideal for labs. |
| Sysinternals Suite | Free Windows utilities such as Process Explorer and Autoruns for investigating processes and persistence. |
| Tool | Notes |
|---|---|
| Wireshark | Free packet analyser; essential for understanding protocols and traffic. |
| tcpdump | Command-line packet capture on Linux and macOS. |
| Zeek | Open-source network monitoring that turns traffic into rich logs. |
| Suricata | Open-source intrusion detection and prevention engine. |
| Security Onion | Free Linux distribution bundling network and host monitoring tools for threat hunting and monitoring. |
Analysts check indicators — IP addresses, domains, URLs and file hashes — against reputation sources many times a day.
| Tool | Use it for |
|---|---|
| VirusTotal | File hashes, URLs, domains and IPs checked against many security vendors. |
| AbuseIPDB | Community reports on malicious IP addresses. |
| urlscan.io | Safely seeing what a URL loads and where it redirects. |
| AlienVault OTX | Community threat intelligence and indicators. |
Be careful what you upload. Files and URLs submitted to public services may be visible to others. Never upload confidential documents or internal data — check your organization’s policy first.
| Tool | Use it for |
|---|---|
| CyberChef | Decoding and transforming data — Base64, URL encoding, hex and obfuscated PowerShell. |
| Email header analysers | Making long email headers readable during phishing investigations. |
| Malware sandboxes (e.g. ANY.RUN, Hybrid Analysis) | Observing what a suspicious file or URL does in an isolated environment. |
Every investigation needs a record. SOC teams use ticketing or case management tools — such as ServiceNow, Jira or the open-source TheHive — to track alerts, evidence, actions and handovers. Good notes in these systems are part of your job, not paperwork.
Tools are only useful when you know what question you are asking. Practice the investigation process in the SOC Analyst simulator and keep our cheat sheet close by.
Tools need a process
Practice realistic SOC investigations from alert to report.
Start free. No experience required.