Beginner SOC Projects: Which One to Build First
Three real, free SOC projects — compared honestly on time, cost, and difficulty, so you can decide where to start instead of guessing.
The three projects
All three are free, all three are documented with a step-by-step guide, and all three prove a genuinely different skill — that’s deliberate, not arbitrary. Pick based on what you have time for and which skill gap matters most for your target role.
Splunk SOC Project
Detect a brute-force login attempt and build a dashboard using Splunk’s free tier.
Build this →Microsoft Sentinel Project
Detect impossible-travel sign-ins — cloud identity security, entirely browser-based.
Build this →Phishing Investigation
Investigate a real phishing email — no software, no cloud account, no cost.
Build this →Compare them honestly
| Project | Time | Setup | Cost | Skill proven |
|---|---|---|---|---|
| Splunk | ~1 hour | Software install, license switch | Free (with limits) | SIEM detection logic, SPL |
| Sentinel | ~1 hour | Azure account, budget alert setup | Free (with limits) | Cloud identity security, KQL |
| Phishing | ~45 min | None — just an email | Free | Header analysis, triage judgment |
Genuinely fastest to start: Phishing Investigation — no install, no account signup, no waiting for anything to provision. It’s also worth knowing it’s not just the “easy” option: phishing is MITRE ATT&CK’s most common initial access technique in real attacks, so this project maps directly to the threat you’re most likely to actually see on the job.
Which one fits your situation?
Start with Phishing
No setup, no waiting. You can realistically finish this in one sitting.
Build it →Start with Splunk
Splunk has been named a Leader in IDC’s independent 2026 SIEM MarketScape assessment — strong first choice if you’re targeting traditional on-prem-focused SOC roles where it’s likely to come up.
Build it →Start with Sentinel
If the roles you’re seeing mention Azure or cloud security specifically, this maps more directly to what you’ll be interviewed on.
Build it →Realistic target: build two, covering different skill types. Splunk or Sentinel plus Phishing gives you both proactive detection and reactive triage — the two core halves of SOC work.
Frequently asked questions
Do I need to build all three projects?
No, but two is a strong minimum — ideally one detection project (Splunk or Sentinel) plus the phishing investigation, since that covers both proactive detection and reactive triage, two distinct SOC skills.
Which project looks best to employers?
None of the three individually — it’s the combination that matters. A single project proves you can follow instructions; two or three covering different skills proves you understand the role.
What if I only have a few hours total?
Start with the Phishing Investigation — it’s the fastest to complete and requires no setup, so it’s the best option if time is genuinely limited.
Built one? Document it properly.
The project only counts once it’s written up the way a hiring manager can actually evaluate.
How to Document Your Project →