CYSE 368/INTERNSHIP FINAL PAPER
SOC Analyst Internship at ManyTek International
Student Name: Dolma Tamang
Date: August 10, 2026
Employer: ManyTek International
Company/Agency: ManyTek International
Supervisor: Emmanuel Damptey
Instructor: Teresa Duvall
Course: CYSE 368/Internship
Term: Summer 2026
TABLE OF CONTENTS
- Introduction
- Management Environment
- Major Work Duties, Assignments, and Projects
- Use of Cybersecurity Skills and Knowledge
- How the ODU Curriculum Prepared Me for the Internship
- Achievement of Internship Learning Objectives
- Most Motivating or Exciting Aspects of the Internship
- Most Discouraging Aspects of the Internship
- Most Challenging Aspects of the Internship
- Recommendations for Future Interns
- Conclusion
1. INTRODUCTION
Being an intern at ManyTek International and completing 150 hours as a SOC Analyst Intern has been one of the most amazing and meaningful experiences of my academic journey. Because of this internship I was able to apply the things I learned inside the classroom to a real-world cybersecurity environment. During internship, I learned to investigate security alerts, understand the purpose of different cybersecurity tools and how they work together, worked in teams, did research on threats and previous cyber incidents, learned to prepare a clear and understandable reports that anyone with or without technical knowledge will be able to understand the process and result.
I begin my internship on May 9, 2026, through July 2026. My supervisor was Emmanuel Damptey. I finished my 150 hours of internship as a SOC analyst in his supervision. I completed this internship as a part of my academic class CYSE 368/Internship at Old Dominion University.
I believe as important as it is to learn the book materials, it is equally important to apply it to the real world and learn from experience. I chose to be a part of this internship because I wanted to see what the real-life SOC environment looks like, what kind of responsibilities a soc analyst has and how do they deal with it. Most importantly I wanted to gain hands on experience and grow my knowledge and experience in real cybersecurity environment as a SOC analyst. Through my academic journey as a cybersecurity student at Old Dominion University, I learned many different concepts of cybersecurity however I wanted to see how these concepts are applied into practical environments. Learning how to use security tools, preparing reports, detecting threats and conducting alert investigations were things I was really interested in learning.
I had learned and understood about the general concepts of cybersecurity in my classroom before the internship, but I had very few experience using real world security platforms in a SOC environment. I was very interested in developing my technical skills and building confidence working with real security tools.
Being an intern at ManyTek International, I was able to accomplish my goals. ManyTek is an amazing and valuable environment to learn about the practical cybersecurity environment. According to ManyTek, it is an operational cybersecurity company that provides cybersecurity operations while also developing the workforce needed to strengthen mission-critical environments.
ManyTek prioritize building operational cybersecurity capabilities, developing cybersecurity professionals while operating across the United States, Ghana, and emerging markets. ManyTek’s specialize in cybersecurity operations, managed detection and response, incident response, threat hunting, detection engineering, SIEM engineering, vulnerability management, and governance and compliance.
ManyTek provides services to many different industries and environment such as federal agencies, enterprise organizations, commercial organizations, government contractors, and nonprofit organizations etc. Since businesses are heavily dependent on technology, they need cybersecurity professionals to work with them to provide continuous monitoring and analysis of their system to identify and respond to potential threats.
I got the opportunity to learn and work with cybersecurity tools such as Microsoft Defender, Microsoft Sentinel, IRIS, Wazuh, and many OSINT tools during my internship. ManyTek also many different cybersecurity tools. Its services show tools like Microsoft Sentinel, Microsoft Defender, Microsoft E5, Wazuh SIEM, Splunk ES, and DFIR-IRIS as part of its security environment.
When I first started the internship, I took part in training and started learning about the different security tools and what processes are used for alert investigations. It was very exciting to learn new things however it was also little challenging. There were so many new information and security platforms which were overwhelming and I had to study different tools and learn to determine what kind of investigations it can be used for.
Investigating security alerts and writing a report was one of my main responsibilities. Every week I had to finish at least one report on the alert investigation and submit it. Because of the repeated process, I got the opportunity to practice alerts investigation, working with security tools, documentation and communication.
During my first 50 hours, I prioritized navigating different cybersecurity tools and understanding how the investigations work. I learned the importance of teamwork because of the team assignments. Working in a team was very helpful, we worked together to understand the problem, share the information’s we found and help each other get through the difficult problems.
During this period of internship, I learned that in cybersecurity it is very important to decide based on facts and not assumptions. It is also important that we focus on every single detail while investigating no matter how small or irrelevant it may appear. In the classroom, it is not surprising to discuss possible scenarios however in real-world investigations, evidence must be present to support the claim on the report. As an SOC analyst there’s no room for assumptions, analysts must conduct the investigation and then make a conclusion based on the evidence.
The four official learning objectives of my internship mentioned in my MOA were to investigate and analyze cybersecurity alerts using SOC tools, develop incident response and threat detection skills, apply threat intelligence and the MITRE ATT&CK framework and improve technical reporting and cybersecurity documentation. Because of these objectives I could see the direction of the internship which also aligned with my personal goals.
During the 150 hours, my skills and knowledge developed significantly. In the first 50 hours, I was overwhelmed by all the information involved while doing the investigation. In the second 50 hours, I gained confidence and became comfortable with the security tools and information’s collected from them. By the final hours, I could investigate the alert comfortably by myself using different tools and platforms to gather information and evidence.
I also got the chance to learn about how artificial intelligence (AI) and cybersecurity work together to create better cybersecurity practice. With the help of AI Analyst could analysts identify suspicious patterns and analyze large amounts of data in a very small amount of time. However, analysts are still equally important as before AI because of the extreme importance of human judgement. AI helps cyber professionals, but it is the responsibility of analysts to investigate and decide.
Overall, I was able to gain a lot of knowledge and understand how real-world SOC operations work because of this internship. It also confirmed that I want to pursue a career in cybersecurity field.
2. MANAGEMENT ENVIRONMENT
One of the important parts of my journey was management environment at ManyTek International. I got the opportunity to do training, team assignments, investigations and communication to strengthen my skills.
When I first started, it was very important that I go through the training on how security tools work and process. In order to understand the alerts and investigate, it is extremely important to understand the platform and how to navigate among them.
They didn’t expect me to understand everything quickly. As I practiced more and gained experience, I was able to understand and learn how the tools work which helped set a foundation for the rest of my internship period.
I was responsible for investigating alerts, researching threats, preparing reports, and working with my teammates. Because of the team assignments, I was able to improve my communication skills and became more comfortable asking questions. Teamwork is essential in cybersecurity because of that large amount of information. Working in team can help solve the problem a lot quicker, different members may find different evidence and ways of looking at the problem.
In the beginning of the internship, I used to require a lot more help with navigating tools and understanding complicated investigations that involved more than 2 devices. Over time, with the help of management environment and practice I became more independent and confident about what tools can be used on different kinds of investigations.
Being an intern at ManyTek gave me a valuable lesson that it is very important to create an environment where people feel comfortable sharing problems and communicating which is also one of the responsibly of management. Cybersecurity is ongoing learning, there is always going to be an unfamiliar situation even as a cyber professional, so it is extremely essential to create a place where questions, advice and discussions are welcomed.
Management environment at ManyTek was very effective because it encourages everyone to share their opinions and questions, teamwork and be independent.
3. MAJOR WORK DUTIES, ASSIGNMENTS, AND PROJECTS
As a SOC analyst intern my main duties involved investigating different types of alerts, using and learning about security tools, researching previous security breach cases, finding evidence, attending meetings and preparing report once a week on specific alerts that I was assigned too. This was also one of the most essential parts of my learning journey because it gave me the opportunity for repeated practice.
An alert only shows what happened in a brief, when it happened and who is involved. Through an investigation using different security I collected information needed to understand the bigger picture of an alert and understand what happened from the beginning to the end. I was able to learn the purpose and functions of different tools because of this process. I gained experience and confidence with using tools like Microsoft Defender, Microsoft Sentinel, IRIS, Wazuh, and OSINT tools.
I used Microsoft Sentinel to gain experience with a security monitoring and investigation platform and Microsoft Defender to learn more about how endpoint and security information works. With the help of OSINT tools, I was able to verify various information.
It is necessary to know the functions and purpose of the security tools. It was hard for me in the beginning to determine what tools are appropriate for what types of investigations however with a lot of practice, I slowly started to become better at it.
In one of my team assignments, we researched and investigated the historical hacks. We
I learned that studying previous cyber-attacks is very valuable. We learned a lot of things like how the attack happened, what techniques were used, how did it affect the party involved etc. Studying attacks can help cybersecurity professionals stay alert and patch any vulnerability that can be exploited.
My communication and teamwork skills have improved a lot due to the team assignments. Each team member took time to discuss the findings and worked with each other to prepare a professional report.
Documenting is one of the most important skills to have as a cybersecurity analyst. As a analyst it’s important to have strong technical documenting skills that can also be understandable to people with non-technical backgrounds because team members will and clients will also be using and reading the information.
Analysts should be able to communicate their discoveries clearly to complete the investigation because teammates and supervisors need to be able to read and understand what was discovered during the investigation, what took place and what was the conclusion that was reached based on the investigation and evidence.
I also became more proficient in using Microsoft Word and Microsoft Excel.
During the last 50 hours of my internships, I got the opportunity to work on advanced alerts that involved many devices. It was challenging because it takes a lot of time to investigate each device and how they are related to each other. SOC analysts are responsible for helping organizations identify and investigate potential threats. It is necessary to review the alerts, so the real attacks are not ignored. To communicate and preserve the conclusion and evidence documentation is essential.
I learned that it is important to have continuous monitoring of the system because cyberattacks can happen anytime so it’s important to have a cyber professional to monitor and analyze security information to determine whether the alert is legitimate or not.
Because of my duties, I was able to gain practical skills with security tools, documentation and communication processes that are important in SOC operations.
I had a prior knowledge of Cybersecurity foundation from my Academic courses, before starting the internship. From my course, I learned about the basic cybersecurity concepts, threats and how important it is to protect the data and information system.
However, in the internship I got the opportunity to apply the things I learned in the class practically and how different it is from classroom learning. Before the internship, I had understood the concept of a true positive and a false positive academically however in the internship I was able to practically learn the difference between these two concepts. I also learned the importance of them in real world security practice. Not every single alert that triggers are malicious and threat. Security analysts are responsible for verifying whether the alert is a threat or false alarm. This taught me how necessary it is to work based on evidence and avoid making assumptions. Single security tools will not be able to show the full picture of the alert, so it is necessary to learn how to connect evidence from different tools and platforms to see the bigger picture of what happened. One of the most important skills to have as a security professional is being able to communicate and document findings clearly. Reports must be organized and clear so anyone reading it should be able to understand them. Because of repeated practice my documentation skills have improved a lot.
It was challenging for me to ask questions and have discussion at the begging of the internship. Working in a team and having a weekly discussion with teammates helped me become comfortable in being able to ask questions, communicate and ask for help. I realized that cybersecurity is not an independent field. It orders to protect the system; teamwork is very necessary. Cyber professionals need to work together to defend the system. During the final hours, I learned the purpose and functions of AI in cybersecurity.
I learned complex problems need to be broken into small pieces in that way different teammates can work on different parts and later come together to form a complete picture of the investigation. In complex alerts, each device needs to be investigated separately which can be very overwhelming.
Overall, I was able to gain hands on experience and technical skills because of the internship. My understanding of cybersecurity transformed a lot by the time I finished the internship.
5. HOW THE ODU CURRICULUM PREPARED ME FOR THE INTERNSHIP
Through my academic course at Old Dominion University, I had understood the foundation of cybersecurity before the internship. I had learned about many different security concepts in my classes that I also encountered during the internship. Including cybersecurity threats, malware, security monitoring, incident response, threat detection, vulnerabilities, and security controls.
Because of the prior knowledge from my academic course, it was helpful to understand the terminology used during investigations. Having an academic foundation helped me focus on learning other things like navigating tools and applying the concept using professional tools.
In school I learned about the importance of monitoring systems and networks but during the internship I got the chance to see how security professionals investigate alerts generated by security platforms. Incident response was one of the connections between my academic course and internship. I had studied previously how the general incident response process works. In the internship, I saw how important documentation and investigation is in the process for an analyst to reach a conclusion.
I understood the necessity of threat detection during the internship. Not every alert generated is malicious, Alert can also be a false alarm. However triggered alert is only the begging, an analyst is responsible whether the alert is actual threat or not.
Experience the concept of true positives and false positives in real SOC environment was much more different and meaningful than studying about it.
I gained critical thinking skills through my course work. In cybersecurity it is required to have critical thinking skills to examine evidence and determine the best solution. I was able to apply these skills directly into my internship.
The biggest difference between my school and the workplace was that in school, I studied security incidents and concepts theoretically but in internship I was able to experience and learn about the concepts and tools in real world situations.
I used professional security tools to work on real alerts. I learned about the SIEM or endpoint security platform in class, but it was very different than navigating it in real time.
Thanks to the internship I got the chance to gain hands on experiment that could not be completely replicated through classroom learning.
Internship expanded my perspective and understanding of documentation. In academic classes I used documentation to demonstrate knowledge but during the internship I learned that professional cybersecurity documentation is used for communication with other people to make them understand the investigation clearly.
In schools’ assignment I did work on groupwork with classmates, however teamwork in professional environment was different. Collaboration has a huge impact on cybersecurity.
Overall, academic courses at ODU helped me prepare well by teaching me the foundation needed to understand cybersecurity. The internship adds hand-on experience and taught me how knowledge are applied in real world SOC environment.
6. ACHIEVEMENT OF INTERNSHIP LEARNING OBJECTIVES
Objective One: Investigate and Analyze Cybersecurity Alerts Using SOC Tools
I was able to fulfill this objective successfully during the internship. I investigated and analyzed Cybersecurity Alerts Using SOC Tools on a daily. It was one of my main responsibilities. I gained experience with security tools.
Objective Two: Develop Incident Response and Threat Detection Skills
I made a huge development towards this objective. Through the internship I learned how cyber professionals investigate the alerts to determine whether it’s a true positive or false positive.
The internship taught me how analysts investigate potential threats and determine whether an alert is a true positive or false positive. I learned how to prepare a report based on information collected, investigate suspicious behavior and rely on facts to reach conclusion.
Although I still have more to learn about advanced incident response, the internship provided a strong foundation.
Objective Three: Apply Threat Intelligence and the MITRE ATT&CK Framework
Threat Intelligence and the MITRE ATT&CK Framework were developed from threat research, historical-hack investigations and different techniques that were used in previous cybersecurity investigations.
Same techniques don’t apply for all types of threats, that is why different investigation techniques are used for different types of threats. I also learned how important it is to have a structured threat analysis. Threat and techniques used by constantly changing in cybersecurity which is why I will continue to develop and learn in this area.
Objective Four: Improve Technical Reporting and Cybersecurity Documentation
Throughout the internship, this objective was strongly fulfilled. I worked on documenting and preparing reports every single week. I practiced how to organize information, document all the information and evidence I collect to prepare a report that explains how the conclusion was reached.
It is extremely important to have strong writing and documenting skills in cybersecurity. Other analysts and team members should be able to understand the investigating clearly through the report.
I fulfilled all four of the learning objectives through the internship. My internship gave me a strong foundation of cybersecurity for continued professional development.
7. MOST MOTIVATING OR EXCITING ASPECTS OF THE INTERNSHIP
The most motivating and exciting aspects of the internship were being able to experience cyber practice in real world environment. Being able to use work with professional security tools was very exciting. It was motivating to be able to see my own growth and progress over time. Starting from being overwhelmed at first 50 hours to being able to use the tools and investigate the alerts independently with confidence was an amazing experience.
I enjoyed working with my teammates in team assignments. It was exciting to work with others who share same goal as you. Sharing information and having discussions with teammates really helped me grow and improve my communication skills. It also gave me a new perspective on how problems can be approached.
Learning about how AI and cybersecurity work together was very interesting because before I had heard a lot about AI taking over the tech jobs. I learned that AI is becoming important, however they work along with Cybersecurity professionals to create better security practice instead of taking over the position of Cybersecurity professionals. Most importantly, I realized that cybersecurity is something I want to pursue my career in.
8. MOST DISCOURAGING ASPECTS OF THE INTERNSHIP
The most discouraging part of my internship was feeling overwhelmed at the beginning of the internship. Security research and investigations contain very big amount of data and information which was discouraging for me as I didn’t’ know what information’s are important. It was also discouraging while I was learning so many new tools.
I had to spend a lot of time practicing and studying. Cybersecurity is ongoing learning; there’s always something new to learn about. It was kind of discouraging for me because no matter how much time I spent learning there’s was always so much to learn. However, I realized that everything seems hard in the beginning, but I must keep going and keep learning. Difficulty
Balancing work, school and internship was challenging for me. So, it became necessary for me to create time management so I could give each other responsibility enough time while working on my alert investigations and report.
Because of this experience, I learned to be organized and patient.
9. MOST CHALLENGING ASPECTS OF THE INTERNSHIP
One of the most changing aspects of my internship was working on complex alerts that involved many devices. Complex alerts are a lot more time-consuming and difficult than alerts that involve 1 to 2 devices.
It was also challenging for me to remember different techniques used for different types of alerts but with overtime, and lots of practice I was able to overcome these challenges. Every new investigation and alerts I worked on gave me the opportunity to learn how new and difficult problems can be solved. It was also challenging for me to remember and learn about different cybersecurity platforms.
When I first started the internship, I found it difficult for me to navigate through different security platforms such as Microsoft Defender, Microsoft Sentinel, IRIS, Wazuh, and OSINT tools but at the end of my internship I was comfortable and confident using these tools and I learned the importance of time management; it was challenging for me to maintain other responsibilities along with the internship. This taught me that organizational skills are equally important as technical skills in cybersecurity professional.
Overall, I was able to grow because of the challenges.
10. RECOMMENDATIONS FOR FUTURE INTERNS
I recommend that future interns review their classroom materials before starting the internship. It is helpful to understand the concepts related to malware, threats, vulnerabilities, security monitoring, incident response, and threat detection.
From my experience, I recommend that they learn about the SIEM systems and endpoint security concepts. Having prior knowledge about the general purpose and function of the platform and tools will make it a lot easier for them to learn even if they have never used exact tools used by the internship organization.
Future interns should be prepared to learn unfamiliar Cybersecurity tools and platforms.
I had difficulty trying to navigate different types of tools, however with practice I got a lot more confident using it. It is important to have clear communication and documentation skills as a cyber professional so I recommend that students should practice documenting and writing skills. Learning and studying about MITRE ATT&CK and threat intelligence before starting a SOC internship is very helpful for the future.
I recommend that if interns have any questions, they should not hesitate to ask them. While it is great to be independent, it is also equally important that interns can work in a team. Teamwork is extremely necessary in cybersecurity. Analysts need to work in a team to communicate and discuss the information’s to fellow teammates.
Time management is very important or else; it is going to be very challenging to manage other responsibilities. I suggest that future interns should create a schedule that way they have enough time for school, work, internship and social life.
Finally, I recommend that they should have a lot of patience. It is going to be challenging and overwhelming at beginning but with practice, time and experience it will get better.
I had some challenges in the beginning of the internship but after practice and time, I learned a lot of valuable skills and confidence. Interns do not have to know everything; they are not expected to. Interns will learn a lot during the internship.
11. CONCLUSION
I learned a lot from my internship at ManyTek International. Completing 150 hours with them was one of the most valuable and amazing experiences of my academic career. I got the chance to apply my academic knowledge to the real-world cybersecurity practice.
When I started the internship, I was nervous and didn’t have much confidence in my skills and ability to work with professional security tools.
First 50 hours, I spent time learning about different security tools, I practice how to navigate tools and alert and worked on team assignments.
Second half of internship, I became comfortable investigating the alerts independently, I also worked on historical attacks research, collecting evidence, documenting and preparing a report.
Final 50 hours of my internship, I continued investigating different types of alerts using security platforms and tools. I worked on team and independently. I gained a lot of experience working with different alerts. I became confident and comfortable in my skills. I also learned about how Artificial intelligence and security analysts work together to create better security practice.
I used to think cybersecurity is all about technical skills however through my internship, I learned that it involves more than technical skills and knowledge. As a cybersecurity professional it is essential to have technical skills, critical thinking, communication, teamwork, documentation, attention to detail, and good judgment.
More than anything, I learned how important the evidence is.
An analyst can only make conclusions based on facts. Analysts cannot assume that an alert is malicious based on assumptions. They must investigate and gather evidence then make a conclusion. I will continue using this approach throughout my cybersecurity career.
Because of this internship, I realized that cybersecurity is something I want to pursue professionally. I will be using my practical experience at ManyTek to my future coursework’s at Old Dominion University.
One of the important takeaways from this internship is that I need to continue working on my technical skills and knowledge.
I want to keep on working on advance security alerts, malware, Incident response and MITRE ATT&CK and AI.
I will continue practicing and improving my documentation and communication skills. Comparing to when I first started the internship and when it ended, I can see that I grew a lot as an analyst and a person. I gained a lot of confidence, technical skills and became comfortable using professional cybersecurity tools.
I learned the importance of breaking down the problems into pieces and how much easier it gets to work on them. Cybersecurity is continuous learning; there’s no end to it. Threats, technology and tools are constantly changing and advancing. Graduating with a cybersecurity degree will be the start of my professional journey in this field and not the end of my learning.
Overall, I am grateful to ManyTek International for providing me with this opportunity to learn. The internship means more to me than a requirement for CYSE 368.
Completing 150 hours of internship gave me confidence in my skills, abilities and myself. It also strengthened my commitment to pursuing cybersecurity as my future career. I will continue working on my skills and knowledge.