CYBRNOX — Beginner SOC Projects: Which One to Build First
ZEROSKILLSPORTFOLIOINTERVIEWHIRED
Portfolio · SOC Projects

Beginner SOC Projects: Which One to Build First

Three real, free SOC projects — compared honestly on time, cost, and difficulty, so you can decide where to start instead of guessing.

6 min read Written by Kevin Byrne Published August 31, 2026

The three projects

All three are free, all three are documented with a step-by-step guide, and all three prove a genuinely different skill — that’s deliberate, not arbitrary. Pick based on what you have time for and which skill gap matters most for your target role.

Splunk SOC Project

Detect a brute-force login attempt and build a dashboard using Splunk’s free tier.

Build this →

Microsoft Sentinel Project

Detect impossible-travel sign-ins — cloud identity security, entirely browser-based.

Build this →

Phishing Investigation

Investigate a real phishing email — no software, no cloud account, no cost.

Build this →

Compare them honestly

ProjectTimeSetupCostSkill proven
Splunk~1 hourSoftware install, license switchFree (with limits)SIEM detection logic, SPL
Sentinel~1 hourAzure account, budget alert setupFree (with limits)Cloud identity security, KQL
Phishing~45 minNone — just an emailFreeHeader analysis, triage judgment

Genuinely fastest to start: Phishing Investigation — no install, no account signup, no waiting for anything to provision. It’s also worth knowing it’s not just the “easy” option: phishing is MITRE ATT&CK’s most common initial access technique in real attacks, so this project maps directly to the threat you’re most likely to actually see on the job.

Which one fits your situation?

Very Limited Time

Start with Phishing

No setup, no waiting. You can realistically finish this in one sitting.

Build it →
Targeting Traditional SOC

Start with Splunk

Splunk has been named a Leader in IDC’s independent 2026 SIEM MarketScape assessment — strong first choice if you’re targeting traditional on-prem-focused SOC roles where it’s likely to come up.

Build it →
Targeting Cloud-First Roles

Start with Sentinel

If the roles you’re seeing mention Azure or cloud security specifically, this maps more directly to what you’ll be interviewed on.

Build it →

Realistic target: build two, covering different skill types. Splunk or Sentinel plus Phishing gives you both proactive detection and reactive triage — the two core halves of SOC work.

Frequently asked questions

Do I need to build all three projects?

No, but two is a strong minimum — ideally one detection project (Splunk or Sentinel) plus the phishing investigation, since that covers both proactive detection and reactive triage, two distinct SOC skills.

Which project looks best to employers?

None of the three individually — it’s the combination that matters. A single project proves you can follow instructions; two or three covering different skills proves you understand the role.

What if I only have a few hours total?

Start with the Phishing Investigation — it’s the fastest to complete and requires no setup, so it’s the best option if time is genuinely limited.

Your Next Step

Built one? Document it properly.

The project only counts once it’s written up the way a hiring manager can actually evaluate.

How to Document Your Project →

Leave a Comment