Présentiel et distanciel
5 days (35 hours)

SOC Analyst Level 1 — detection, analysis and incident response

The security operations centre is an organization's first line of defence, and qualifying an alert is a profession in its own right. This course prepares for the level 1 analyst role: understanding attacker tradecraft, using an event collector, qualifying, investigating and triggering the appropriate response.

Training objectives

  • Understand how a security operations centre is organized and the analyst's role.
  • Master the fundamentals: logging, telemetry, threat frameworks.
  • Use an event collector: collection, normalization, correlation.
  • Qualify an alert, rule out false positives and document an investigation.
  • Analyse common incidents: compromised account, phishing, lateral movement.
  • Apply a response plan and write an actionable incident report.

Target audience

  • Aspiring analysts and technicians moving into security.
  • Systems and network administrators transitioning to cybersecurity.
  • Support teams required to handle security alerts.

Prerequisites

  • Linux and Windows systems basics.
  • Sound understanding of TCP/IP networking.

Detailed program

Day 1 — Foundations of defence

  • Security operations centre organization, tiers and processes
  • Threats, tradecraft and the attack chain
  • Adversary technique framework and detection use cases

Day 2 — Logs and telemetry

  • System, network and application log sources
  • Event collection, normalization and enrichment
  • Network detection and flow analysis

Day 3 — Working with the event collector

  • Getting started with the platform and event searching
  • Correlation rules, thresholds and noise reduction
  • Dashboards and indicator tracking

Day 4 — Investigation

  • Alert qualification methodology
  • Analysing an account compromise and a phishing campaign
  • Analysing a compromised host and hunting for lateral movement

Day 5 — Response and reporting

  • Incident response plan and containment actions
  • Threat intelligence and indicators of compromise
  • Writing the incident report and closing exercise

Certification

At the end of this training, you will receive a certificate of participation issued by squint.

Price on request

Duration

5 days (35 hours)

Format

Présentiel et distanciel

Next session

On request

Request a quote

Other training courses that might interest you

FreeIPA and Red Hat IDM — centralized identity management on Linux

Présentiel et distanciel

FreeIPA, and its supported counterpart Red Hat Identity Management, bring to the Linux world what Active Directory offers to Windows: …

3 days (21 hours) Learn more

Linux hardening and CIS compliance with Ansible

Présentiel et distanciel

Server hardening remains the best ratio between effort and risk reduction. It still has to be applied consistently, reproducibly and …

2 days (14 hours) Learn more

Ready to develop your skills?

Join hundreds of professionals who have trusted squint for their skills.

View all our training courses