Upper-intermediate 6 topic areas 46+ exercises

SOC Analyst / Threat Hunter

SOC Analysts and Threat Hunters monitor security telemetry, investigate alerts, and communicate findings to technical and non-technical audiences. Their English work includes writing escalation reports, documenting investigation timelines, producing threat intelligence summaries, and communicating incident impact to management. This path builds the language of proactive and reactive security operations.

Topics covered

  • Alert triage & investigation
  • Threat hunting
  • MITRE ATT&CK
  • SIEM & SOAR operations
  • Threat intelligence
  • Incident escalation

Vocabulary spotlight

4 terms every SOC Analyst / Threat Hunter should know in English:

IOC (Indicator of Compromise) n.

Evidence that a system has been breached: a malicious IP, hash, domain, or behavioural pattern observed after the fact

"The threat actor's C2 server IPs were added to our IOC blocklist within 30 minutes of identification."
threat hunting n.

A proactive security practice of searching through systems for adversary activity that has evaded automated detection

"During threat hunting, the analyst found lateral movement that SIEM rules had not triggered on."
MITRE ATT&CK n.

A knowledge base of adversary tactics, techniques, and procedures (TTPs) used as a framework for describing and categorising attack behaviour

"The intrusion mapped to T1566.001 (Spearphishing Attachment) in the MITRE ATT&CK framework."
false positive n.

An alert that fires for benign activity that resembles malicious behaviour — the alert is technically correct but the activity is not a real threat

"After tuning the rule, we reduced false positives from 200/day to under 10."
Open full glossary →

📚 Vocabulary Reference

Key terms organised by category for SOC Analyst / Threat Hunters:

Detection & Alerting

SIEMSOARalertruletuningfalse positivetrue positivenoise reductionbaselineanomaly detectionplaybook

Threat Intelligence

IOCIOATTPthreat actorAPTcampaignMITRE ATT&CKtacticstechniqueprocedurethreat feedSTIX/TAXII

Investigation

triagealert investigationroot causelateral movementpivottimelinekill chainforensic artefactlog analysisthreat hunting

Communication

escalationseverity ratingconfidence levelimpact assessmentcontainmentremediationexecutive summaryincident reportlessons learned
Study full vocabulary modules →

Recommended exercises

Real-world scenarios you'll practise

  • Writing an escalation report for a suspected credential stuffing attack — factual, investigation-led
  • Summarising a threat hunting finding for the CISO: TTP mapping, affected systems, confidence level
  • Explaining the difference between a false positive and a true positive to a junior analyst
  • Writing a post-incident IOC report that external partners can use for threat sharing

Recommended reading

Explore another role

🚨 Incident Commander

Open path →

Frequently Asked Questions

What English skills do SOC Analyst / Threat Hunters most need to improve?+

SOC Analyst / Threat Hunters most commonly need to improve: technical vocabulary (the correct English terms for domain concepts), collocation accuracy (using the right verb for each action), written communication (bug reports, PR descriptions, technical docs), and spoken communication for standups, code reviews, and stakeholder meetings.

How long does the SOC Analyst / Threat Hunter learning path take?+

The SOC Analyst / Threat Hunter learning path contains 20–40 hours of material studied comprehensively. Most learners focus on the highest-priority modules first and return to the rest over time. Spending 30 minutes per day for 4–6 weeks produces noticeable improvement in workplace English.

What vocabulary should a SOC Analyst / Threat Hunter prioritise first?+

Start with the vocabulary that appears most in your daily work — terms you read in documentation, use in commit messages, and hear in meetings. The SOC Analyst / Threat Hunter path begins with the most frequent vocabulary clusters before moving to advanced communication patterns.

Are there interview exercises for SOC Analyst / Threat Hunter roles?+

Yes. The SOC Analyst / Threat Hunter path includes role-specific interview question modules with model answers and key phrases — the actual questions interviewers ask and the vocabulary needed to answer them fluently. There is also a dedicated Interview Practice hub for general interview skills.

Does this path include pronunciation help?+

Yes. The path links to pronunciation exercises for the technical terms most commonly mispronounced in this domain. The Pronunciation hub includes drills for acronyms, silent letters, word stress, and minimal pairs — all in IT context.

What are the most common English mistakes SOC Analyst / Threat Hunters make?+

The most common mistakes: incorrect collocations (using the wrong verb with a technical noun), false friends from L1, tense errors when narrating past incidents or walkthroughs, and using overly formal or overly casual register in written communication.

How do I improve my English for code reviews?+

Learn the standard code review collocations: approve a PR, request changes, leave a nit, address feedback, block a merge, resolve a conversation. Use hedging language for suggestions: "This might be cleaner as…", "Have you considered…?". The Collocations section includes a dedicated Code Review set.

Can I use this path alongside my daily work?+

Yes — the path is designed for working professionals. Each exercise set takes 10–15 minutes. The most effective approach is to study a vocabulary module before a meeting or task where you'll use that vocabulary, then practise immediately after. Context-linked practice produces much faster retention.

Is the content free?+

Yes, completely free. No registration required, no payment, no time limit. All vocabulary modules, exercises, glossary entries, and learning path guides are open access.

How do I track my progress through this path?+

Progress is tracked in your browser's local storage — completed exercise sets are marked with a checkmark when you return. No account is needed. You can bookmark specific modules and use the exercises overview to see which sets you've completed.