SOC Analyst Level 1 — detection, analysis and incident response
The security operations centre is an organization's first line of defence, and qualifying an alert is a profession in its own right. This course prepares for the level 1 analyst role: understanding attacker tradecraft, using an event collector, qualifying, investigating and triggering the appropriate response.
Training objectives
- Understand how a security operations centre is organized and the analyst's role.
- Master the fundamentals: logging, telemetry, threat frameworks.
- Use an event collector: collection, normalization, correlation.
- Qualify an alert, rule out false positives and document an investigation.
- Analyse common incidents: compromised account, phishing, lateral movement.
- Apply a response plan and write an actionable incident report.
Target audience
- Aspiring analysts and technicians moving into security.
- Systems and network administrators transitioning to cybersecurity.
- Support teams required to handle security alerts.
Prerequisites
- Linux and Windows systems basics.
- Sound understanding of TCP/IP networking.
Detailed program
Day 1 — Foundations of defence
- Security operations centre organization, tiers and processes
- Threats, tradecraft and the attack chain
- Adversary technique framework and detection use cases
Day 2 — Logs and telemetry
- System, network and application log sources
- Event collection, normalization and enrichment
- Network detection and flow analysis
Day 3 — Working with the event collector
- Getting started with the platform and event searching
- Correlation rules, thresholds and noise reduction
- Dashboards and indicator tracking
Day 4 — Investigation
- Alert qualification methodology
- Analysing an account compromise and a phishing campaign
- Analysing a compromised host and hunting for lateral movement
Day 5 — Response and reporting
- Incident response plan and containment actions
- Threat intelligence and indicators of compromise
- Writing the incident report and closing exercise
Certification
At the end of this training, you will receive a certificate of participation issued by squint.
Other training courses that might interest you
FreeIPA and Red Hat IDM — centralized identity management on Linux
Présentiel et distancielFreeIPA, and its supported counterpart Red Hat Identity Management, bring to the Linux world what Active Directory offers to Windows: …
Linux hardening and CIS compliance with Ansible
Présentiel et distancielServer hardening remains the best ratio between effort and risk reduction. It still has to be applied consistently, reproducibly and …
Ready to develop your skills?
Join hundreds of professionals who have trusted squint for their skills.
View all our training courses