Skip to main content
SOC & security engineering courses

Learn to investigate threats and build better detections.

Learn to investigate alerts, analyse security logs in Splunk, and design detections. Compare our SOC Level 2, Detection Engineering, and Security Engineering L3 courses to find the right level, practical focus, and entry requirements.

  • Three focused courses
  • Practical course outlines
  • Clear entry requirements

Illustration of an alert investigation

Choose a course

Which course fits your experience?

Start with investigations, specialize in detection engineering, or broaden your advanced security practice. Compare the focus of each course below.

Each course page lists its syllabus and prerequisites. Check the format and platform access details before enrolling so you know what to expect.

Not sure where you fit? Ask us about the courses →

How training works

Learn the method, then use it.

The course outlines move from core concepts to practical application and clear reasoning. Specific exercises and delivery arrangements vary by course.

  1. Learn the method

    Build the concepts behind an investigation or detection before moving into the tools. Check the course page for its delivery format and support.

  2. Apply it in practice

    Depending on the course, investigate alerts, query logs, test detection logic, or examine endpoint and cloud activity.

  3. Explain your decisions

    Use the evidence to support a conclusion, explain your detection choices, and describe the action you would take next.

For enrolled learners

Your lessons and labs live in the learner portal.

This website helps you choose a course. Once your access is approved, use the separate CyberAccend learner portal to open assigned lessons, take quizzes, and work through published hands-on labs.

Portal access requires approval. Course assignments and lab availability vary.

Inside the portal

One place to learn and practise

Learner workspace
  1. Work through your course

    Open assigned modules, read lessons, and check what you have learned with quizzes.

  2. Investigate in Cyber Labs

    Read a case briefing, examine the available evidence or tools, and submit your findings.

  3. See your progress

    Return to your course to see completed lessons and pick up where you left off.

Course syllabus

See what you'll study.

Preview the first four modules in any course. Open the course details for the full syllabus, practical activities, and entry requirements.

Showing the first four modules of SOC Level 2 Analyst Training.

Module 014 Hours

SOC Operations & Cybersecurity Foundations

Topics include

  • SOC architecture and workflow
  • Roles and responsibilities of SOC analysts
  • SOC metrics and SLAs
Module 025 Hours

Malware Analysis & OS Internals

Topics include

  • Windows architecture
  • Processes and threads
  • Registry analysis
Module 037 Hours

SIEM & Splunk Operations

Topics include

  • Log sources and log pipelines
  • Event correlation
  • Splunk architecture
Module 046 Hours

Advanced Log Analysis & Investigation

Topics include

  • Windows Event Logs
  • Authentication events
  • Sysmon logs
Optional mentorship

Need help with a specific next step?

Request focused guidance if you are choosing a role, working through a technical topic, or preparing for an interview. Session details are confirmed before booking.

Choose a direction

Review your target role, current skills, and practical learning priorities.

Work through a technical topic

Get focused guidance on SOC, detection, endpoint, or cloud-security concepts.

Prepare for interviews

Practice explaining investigations and technical decisions in role-specific questions.

Your next step

Not sure which course is right for you?

Tell us about your current experience and what you want to learn. We can help you compare SOC Level 2, Detection Engineering, and Security Engineering L3.