Cybersecurity · Beginner → Expert
🛰️ SOC Analyst and Security Operations
Develop blue-team skills for monitoring, SIEM, endpoint and network telemetry, detection engineering, threat intelligence, triage, incident response and reporting.
Course roadmap
Pass each module exam to unlock the next module.
Module 1 · Beginner
SOC Operations, Roles, Escalation and Case Management
Locked
Module 2 · Beginner
Security Logs, Telemetry and Event Normalization
Locked
Module 3 · Beginner
SIEM Architecture, Search and Correlation
Locked
Module 4 · Beginner
Windows Security Events and Endpoint Telemetry
Locked
Module 5 · Intermediate
Linux Logs and Server Telemetry
Locked
Module 6 · Intermediate
Network Security Monitoring and Traffic Analysis
Locked
Module 7 · Intermediate
Email Security and Phishing Investigation
Locked
Module 8 · Intermediate
Identity, Authentication and Cloud Audit Events
Locked
Module 9 · Advanced
Detection Engineering and Alert Logic
Locked
Module 10 · Advanced
Threat Intelligence and Indicator Handling
Locked
Module 11 · Advanced
Alert Triage, Scoping and Prioritization
Locked
Module 12 · Advanced
Malware Triage and Safe Analysis Concepts
Locked
Module 13 · Expert
Incident Response Containment and Eradication
Locked
Module 14 · Expert
Threat Hunting Methodology
Locked
Module 15 · Expert
Reporting, Evidence and Metrics
Locked
Module 16 · Expert
Expert Capstone: SOC Investigation Simulation
Locked
Certification gate
Final course exam
Pass mark: 80%. Time limit: 360 minutes. All module exams must be passed first.
Locked until modules are passed