"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to Security Operations Centers
- SOC fundamentals
- SOC objectives
- Security operations lifecycle
- SOC team structure
- Analyst responsibilities
- Security monitoring overview
Module 2: Cybersecurity Fundamentals for SOC Analysts
- Security principles
- Threat landscape
- Attack surfaces
- Vulnerabilities
- Security controls
- Defense-in-depth
Module 3: Networking for SOC Operations
- TCP/IP fundamentals
- Ports and protocols
- DNS
- HTTP and HTTPS
- Network devices
- Network traffic fundamentals
Module 4: Operating System Security
- Windows security
- Linux security
- User accounts
- Processes and services
- System events
- Security configurations
Module 5: Security Monitoring Fundamentals
- Monitoring strategies
- Security telemetry
- Event collection
- Alert generation
- Security baselines
- Continuous monitoring
Module 6: Log Management & Analysis
- Log sources
- Windows event logs
- Linux logs
- Application logs
- Log correlation
- Investigation techniques
Module 7: SIEM Fundamentals
- SIEM architecture
- Data ingestion
- Event correlation
- Search and queries
- Dashboards
- Alert management
Module 8: Network Security Monitoring
- Network traffic analysis
- Firewall logs
- IDS/IPS alerts
- DNS monitoring
- Proxy logs
- Suspicious traffic identification
Module 9: Endpoint Security Monitoring
- Endpoint telemetry
- Endpoint Detection and Response
- Process monitoring
- File activity
- User activity
- Endpoint alerts
Module 10: Threat Intelligence
- Threat intelligence fundamentals
- Intelligence sources
- Indicators of compromise
- Threat context
- Intelligence enrichment
- Threat intelligence lifecycle
Module 11: Cyber Threat Detection
- Detection concepts
- Signature-based detection
- Behavioral detection
- Anomaly detection
- Threat indicators
- Detection validation
Module 12: Alert Triage & Prioritization
- Alert classification
- Severity assessment
- False positives
- Alert enrichment
- Risk prioritization
- Escalation procedures
Module 13: Security Incident Investigation
- Investigation methodology
- Evidence gathering
- Timeline development
- Event correlation
- Root cause analysis
- Investigation documentation
Module 14: Malware Analysis Fundamentals
- Malware categories
- Malware indicators
- Static analysis concepts
- Behavioral analysis
- Suspicious files
- Malware investigation
Module 15: Phishing Investigation
- Phishing indicators
- Email headers
- Suspicious URLs
- Attachment analysis
- Sender analysis
- Investigation workflow
Module 16: Incident Response
- Incident lifecycle
- Identification
- Containment
- Eradication
- Recovery
- Post-incident review
Module 17: MITRE ATT&CK for SOC Operations
- ATT&CK framework
- Tactics
- Techniques
- Detection mapping
- Investigation context
- Defensive use cases
Module 18: Threat Hunting
- Threat hunting fundamentals
- Hypothesis development
- Data exploration
- Indicator-based hunting
- Behavioral hunting
- Hunting documentation
Module 19: Detection Engineering
- Detection logic
- Detection rules
- Use case development
- Rule tuning
- False-positive reduction
- Detection improvement
Module 20: SOC Automation & SOAR
- Security automation
- SOAR fundamentals
- Response playbooks
- Alert enrichment
- Workflow automation
- Analyst productivity
Module 21: SOC Metrics & Reporting
- Security metrics
- Key performance indicators
- Incident metrics
- SOC dashboards
- Management reporting
- Continuous improvement
Module 22: Practical SOC Investigation
- Alert triage
- Log investigation
- Network analysis
- Endpoint investigation
- Incident escalation
- Investigation reporting
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device