Skip to main content

Explore training paths

Practical cybersecurity training for SOC analysts and security engineers.

Choose a course by the work you want to practise: investigate alerts and search logs in SOC Level 2, build and test rules in Detection Engineering, or develop broader Splunk, endpoint, and cloud skills in Security Engineering L3.

Compare programs

Which program is right for you?

Start with SOC Level 2 for investigations. Choose Detection Engineering if you want to write and test alert logic. Security Engineering L3 covers a broader mix of Splunk, endpoint, cloud, and automation work.

Intermediate to Advanced30–35 Hours 6 modules

Investigate & respond

SOC Level 2 Analyst Training

Learn to investigate security alerts, connect evidence across tools, and decide what to do next.

Best for

Blue-team practitioners, incident responders, and learners with networking and operating-system basics who want deeper SOC investigation skills.

You'll practice

  • Triage alerts from logs, devices, email, and network traffic
  • Investigate malware and suspicious endpoint behavior
  • Build Splunk detections and document incident findings
Intermediate to Advanced35 Hours 8 modules

Build & tune alerts

Detection Engineering

Turn raw security logs into detections you can test, explain, and improve.

Best for

SOC analysts and incident responders who can already investigate alerts and want to start writing detection logic.

You'll practice

  • Choose the right telemetry for an attacker behavior
  • Write and test identity, endpoint, network, and cloud detections
  • Tune noisy results and document a final detection pack
Advanced35 Hours 7 modules

Broader security engineering

Security Engineering L3

Build, test, and improve detections across Splunk, Microsoft Defender, and AWS.

Best for

SOC L2/L3 analysts and security, detection, or cloud engineers who already investigate incidents and search security logs.

You'll practice

  • Design and tune threat detections in Splunk and Sigma
  • Hunt for threats with Microsoft Defender for Endpoint
  • Investigate AWS activity and automate security tasks

Looking for Splunk training?

Splunk is part of several courses, not a separate certification class. In SOC Level 2, you cover SIEM fundamentals and log investigations. In Detection Engineering, you write and validate alerts with SPL. Security Engineering L3 covers advanced Splunk operations and correlation rules.

How you’ll learn

Learn the concepts, then use them.

Every course starts with the evidence and ends with work you can explain. Delivery and platform access for Detection Engineering are confirmed before enrolment.

Start with the evidence

Learn which logs matter and what questions to ask before choosing a tool or query.

Practice a real workflow

Work through investigation or detection-design exercises matched to your program.

Explain your decisions

Show how you reached a conclusion, tested a rule, or decided what to do next.

After enrolment

Your lessons and labs live in the learner portal.

This website helps you compare courses. Approved learners use the separate CyberAccend learner portal for assigned lessons and published labs.

01 / Learn

A workspace for your assigned course

Read lessons, complete knowledge checks, and keep track of your progress in one place. The portal is for approved learners; browsing this public site does not create course access.

02 / Investigate

Explore SOC investigation labs

Published Cyber Labs let approved learners review a case briefing, examine security evidence, and answer investigation questions. The public practice center offers previews; the lab workspace is in the learner portal.

Need help choosing?

Tell us what you know and what you want to learn.

Tell us which tools you've used, what kinds of alerts you've investigated, and what you'd like to learn next. We'll help you find the better starting point.

Ask for guidance