Course Overview
This comprehensive course is designed to equip you with the practical skills required to excel in the field. Built by industry experts, it covers everything from fundamentals to advanced concepts through interactive, real-world simulations.
What You'll Learn
- Understand core concepts of SOC Analyst & SIEM Engineering
- Hands-on experience with industry-standard tools
- Real-world scenario simulations and labs
- Preparation for certification exams
Tools Covered
Full Syllabus
Key Topics
- Tier 1/2/3 Roles
- Incident Triage Workflow
- Metrics and KPIs
- Compliance Requirements
Hands-on Labs
- Ticket Creation and Escalation in TheHive
- Defining SOC SLAs
Key Topics
- SIEM Architecture
- Log Ingestion Methods
- Syslog
- Agents vs Agentless
Hands-on Labs
- Deploying Splunk Universal Forwarders
- Configuring Filebeat for Elastic
Key Topics
- Regex (Regular Expressions)
- Field Extractions
- Common Information Model (CIM)
Hands-on Labs
- Writing Regex to Extract Custom Log Fields
- Mapping Data to Splunk CIM
Key Topics
- Search Processing Language (SPL)
- Aggregations
- Visualizations and Dashboards
Hands-on Labs
- Building Executive Security Dashboards
- Hunting for Anomalies using SPL
Key Topics
- Use Case Development
- Correlation Rules
- Tuning and False Positives
Hands-on Labs
- Building Brute-Force Alert Rules
- Detecting Pass-the-Hash Attacks
Key Topics
- STIX/TAXII
- Integrating MISP
- IoC Matching
Hands-on Labs
- Ingesting Threat Feeds into SIEM
- Alerting on Known Bad IPs
Key Topics
- SOAR Concepts
- Playbooks
- Automated Enrichment
- Automated Containment
Hands-on Labs
- Building a Playbook in Cortex XSOAR
- Automating IP Blocking on Firewalls
Key Topics
- Ransomware Outbreak
- Insider Threat
- Data Exfiltration
Hands-on Labs
- Full Simulated Incident Response Exercise
- Post-Incident Reporting
Key Topics
- Application of Learned Concepts
- End-to-End Task Execution
- Problem Solving and Analytical Thinking
- Structured Documentation
Hands-on Labs
- Guided Practical Exercises
- Scenario-Based Labs
- Independent Practice Tasks
Instructors
Certificate of Completion
Certificate of Completion
This is to proudly certify that
has successfully completed the comprehensive training requirements for