Skip to main content
Cybersecurity training paths

Learn to investigate threats and build better detections.

Choose a course that matches your work: SOC investigation, detection engineering, or broader security engineering. Compare the skills, prerequisites, and course outlines before you decide where to start.

  • Three focused courses
  • Practical course outlines
  • Clear entry requirements

Illustration of an alert investigation

Choose a course

Which course fits your experience?

Start with investigations, specialize in detection engineering, or broaden your advanced security practice. Compare the focus of each course below.

Each course page lists its syllabus and prerequisites. Check the format and platform access details before enrolling so you know what to expect.

Not sure where you fit? Ask us about the courses →

How training works

Learn the method, then use it.

The course outlines move from core concepts to practical application and clear reasoning. Specific exercises and delivery arrangements vary by course.

  1. Learn the method

    Build the concepts behind an investigation or detection before moving into the tools. Check the course page for its delivery format and support.

  2. Apply it in practice

    Depending on the course, investigate alerts, query logs, test detection logic, or examine endpoint and cloud activity.

  3. Explain your decisions

    Use the evidence to support a conclusion, explain your detection choices, and describe the action you would take next.

Course syllabus

See what you'll study.

Preview the first four modules in any course. Open the course details for the full syllabus, practical activities, and entry requirements.

Showing the first four modules of SOC Level 2 Analyst Training.

Module 014 Hours

SOC Operations & Cybersecurity Foundations

Topics include

  • SOC architecture and workflow
  • Roles and responsibilities of SOC analysts
  • SOC metrics and SLAs
Module 025 Hours

Malware Analysis & OS Internals

Topics include

  • Windows architecture
  • Processes and threads
  • Registry analysis
Module 037 Hours

SIEM & Splunk Operations

Topics include

  • Log sources and log pipelines
  • Event correlation
  • Splunk architecture
Module 046 Hours

Advanced Log Analysis & Investigation

Topics include

  • Windows Event Logs
  • Authentication events
  • Sysmon logs
Optional mentorship

Need help with a specific next step?

Request focused guidance if you are choosing a role, working through a technical topic, or preparing for an interview. Session details are confirmed before booking.

Choose a direction

Review your target role, current skills, and practical learning priorities.

Work through a technical topic

Get focused guidance on SOC, detection, endpoint, or cloud-security concepts.

Prepare for interviews

Practice explaining investigations and technical decisions in role-specific questions.

Your next step

Not sure which course is right for you?

Tell us about your current experience and what you want to learn. We can help you compare SOC Level 2, Detection Engineering, and Security Engineering L3.