Curriculum
Module 1: Security Operation Centre
- Understand SOC fundamentals
- Discuss SOC components: people, processes, and technology
- Understand SOC implementation
Module 2: Understanding Cyber Threat and Attack Methodology
- Describe cyber threats and attacks
- Understand network-level attacks
- Understand host-level attacks
- Understand application-level attacks
- Understand Indicators of Compromise (IoCs)
- Discuss the attacker's hacking methodology
Module 3: Incident Detection in a SIEM Environment
- Understand basic concepts of Security Information and Event Management (SIEM)
- Discuss different SIEM solutions
- Understand SIEM deployment
- Use case examples: application-level incident detection
- Use case examples: insider incident detection
- Use case examples: network-level incident detection
- Use case examples: host-level incident detection
- Use case examples: compliance
- Understand alert triaging, handling, and analysis
Module 4: Incident Response
- Understand fundamental concepts of incident response
- Learn the phases of the incident response process
- Respond to network security incidents
- Respond to application security incidents
- Respond to email security incidents
- Respond to insider incidents
- Respond to malware incidents
Module 5: Incident Events and Logging
- Understand fundamentals of incidents, events, and logging
- Explain local logging concepts
- Explain centralised logging concepts
Module 6: Vulnerability Management
- Understand vulnerability management fundamentals
- Identify, assess, and prioritise vulnerabilities
- Support remediation and reporting in a SOC context
Hands-On Labs and Live Projects
Splunk — Monitoring and Alerts
Learn to use Splunk, a leading SIEM tool, to collect, search, analyse, and visualise log data from servers, firewalls, endpoints, and other sources.
Wireshark — Network Traffic Analysis
Capture and inspect live network traffic; detect suspicious packets, analyse protocols, and identify indicators of compromise (IoCs) in network activity.
MITRE ATT&CK Framework
Explore how real-world attackers operate; map attack techniques to detection strategies using logs and threat intelligence.
Linux — Log Analysis
Analyse logs to identify brute-force attacks, privilege escalation, and unauthorised access using command-line tools such as `grep`, `awk`, and `journalctl`.
Career Outcomes
- SOC Analyst
- Information Security Officer
- Security Consultant
- Security Engineer
Included Benefits
- Industry expert-led instruction
- Hands-on SOC tools and live projects
- Resume guidance and mock interviews
- Profile marketing and LinkedIn optimisation
#Keywords and Tags
soc, security-operations-center, cybersecurity, siem, splunk, incident-response, threat-detection, wireshark, mitre-attack, linux, soc-analyst, beginner-cybersecurity