Program Overview
The TechPeak Lab SOC Analyst (Cybersecurity) internship simulates life on an entry-level SOC team. Over 12 weeks you will:\n\n- Work from SIEM alerts and raw logs to validate or dismiss incidents.\n- Build repeatable playbooks for common attack patterns.\n- Perform basic threat hunting using log and endpoint data.\n- Produce concise updates and after-action reports.\n\nYour final portfolio will show how you approach noisy data, prioritise risk, and collaborate with the wider security function.
Skills You'll Gain
Tools & Technologies
Internship Structure
This 12-week internship is structured around hands-on project work. Each week builds upon the previous, introducing new concepts and challenges that mirror real industry scenarios.
You'll work independently on projects, receive structured feedback, and have the opportunity to refine your work based on instructor guidance.
Projects
Week 1 project preview
Build a Basic SIEM Monitoring Lab
Your first week as a SOC analyst intern is about wiring up visibility. You will stand up a lightweight SIEM-style lab, ingest logs, and prove that you can actually see suspicious activity as it happens.
Requirements
- Set up a log collection and analysis stack using Wazuh, ELK, or a similar open-source tool. - Ingest host or application logs from at least one test system (VM, local machine, or lab host). - Simulate a handful of suspicious events (failed logins, privilege changes, simple port scans, etc.). - Create at least two detection rules or saved searches that reliably surface these simulated events. - Document the end-to-end flow from log source → collection → indexing → visualization/detection.
Deliverables
- Step-by-step setup guide (`SETUP.md` or included in `README.md`) with screenshots of your SIEM or monitoring dashboard. - Written description of each simulated attack or suspicious activity and why it matters. - Screenshots or exports of alerts, dashboards, or queries showing your detections firing. - A short incident-style summary for at least one simulated event, written as if you were reporting to a lead analyst.
Build a Basic SIEM Monitoring Lab
Your first week as a SOC analyst intern is about wiring up visibility. You will stand up a lightweight SIEM-style lab, ingest logs, and prove that you can actually see suspicious activity as it happens.
Later weeks
Week 2 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 3 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 4 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 5 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 6 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 7 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 8 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 9 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 10 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 11 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.
Week 12 project
Detailed brief available once you are enrolled.
Create an account and enroll to see the full weekly briefs.