- SOC architecture and workflow
- Roles and responsibilities of SOC analysts
- SOC metrics and SLAs
- Alert lifecycle management
- CIA Triad
- Defense in Depth
- Common security controls
- Attack vectors
- Cyber Kill Chain
- MITRE ATT&CK deep dive
- NIST & CIS Controls
- SIEM, EDR/XDR, IDS/IPS, Firewalls
- Ransomware, phishing & credential attacks
Instructor-led training · Hands-on practice
SOC Level 2 Analyst Training
Investigate alerts using SIEM, endpoint, identity, email, and network evidence, then decide how to respond.
Course at a glance
Learn to investigate security alerts and decide what to do next.
Learn how a SOC investigation works, from alert to response.
This instructor-led, intermediate-to-advanced course teaches you to investigate alerts, analyse logs and malware, search SIEM data, and use endpoint evidence. Guided labs follow realistic attack scenarios—from initial triage and scope to detection and response decisions.
Core focus
Is this training right for you?
Check the background expected before you explore the full curriculum.
Who it’s for
- Security Engineers
- Incident Responders
- Blue Team professionals
- Cybersecurity students
What you should know first
- Basic understanding of networking, operating systems, and cybersecurity concepts
- Familiarity with common attack types and security controls
- Some exposure to logs, command-line tools, or SOC workflows is helpful
How you’ll practise
- SOC Analyst interview questions
- MCQs & quizzes
- Real-world investigation scenarios
- Detection challenges
- Hands-on assignments
- Incident-investigation exercise
Practise a complete SOC investigation.
Learn how to move from an alert to a conclusion you can support with evidence.
Search Splunk and other SIEM data alongside Windows Event Logs, Sysmon, endpoint activity, email evidence, and network traffic. You’ll validate an alert, work out what was affected, and build a timeline of what happened.
Guided labs cover phishing, malware, EDR alerts, detection engineering, and threat hunting. Assessments look at the evidence you collect, the decisions you make, and how clearly you report your findings.
Skills you’ll practise in this course.
Each outcome is tied to practical investigation or engineering work.
- Investigate and triage SOC alerts effectively
- Perform advanced log analysis across Windows, Linux, and network sources
- Analyze Windows Event Logs and Sysmon events for malicious activity
- Detect malicious behavior using SIEM (Splunk) and EDR platforms
- Conduct full malware investigations using static and dynamic techniques
- Build custom detections, dashboards, and correlation rules
- Investigate phishing campaigns and web-based attacks
- Perform structured threat hunting using multiple methodologies
- Handle real-world SOC incidents confidently, end-to-end
Splunk training within SOC Level 2.
The seven-hour SIEM and Splunk module is part of this SOC analyst course, not a separate standalone course.
Start with the path security data takes into a SIEM. Then use Splunk Search Processing Language (SPL) to find events, narrow results, and connect activity across Windows and Sysmon logs. You’ll also work with dashboards, alert creation, and tuning.
For example, you might search for repeated failed logins, find a later successful login, and check the same host for unusual process activity. The goal is to explain what the evidence supports—not just return a matching event.
Tools you’ll work with.
See the platforms and methods used throughout the lessons and labs.
What you’ll produce.
Build practical work you can discuss and explain, not just a record of attendance.
- SOC alert triage and escalation record
- Windows and Sysmon investigation timeline
- SPL detection query with tuning notes
- Phishing-analysis report
- Malware sandbox investigation summary
- Endpoint compromise case report
Assessment standards
Completion is based on applied work, not attendance alone.
- Accuracy of alert triage and prioritization
- Quality of evidence collection and investigation pivots
- Clarity of scope, impact, and containment recommendations
- Detection logic quality and false-positive awareness
- Completeness of the final investigation report
Safe lab conduct
Exercises remain inside authorized, isolated training environments.
- Use only the isolated training environment and authorized datasets
- Never upload confidential or production data to public analysis services
- Keep malware samples and simulations inside the designated lab workflow
- Document investigation steps and restore or clean up the lab after each exercise
Explore the 6 course modules.
Open a module to see its topics and hands-on exercises.
Put the lessons into practice.
Use lab evidence and security tools to work through investigation and response decisions.
Investigation labs
- Windows Event Log Analysis
- Threat Hunting Labs
- Sysmon Investigation
- Phishing Investigation
- Malware Sandbox Analysis
- Adversary Simulation Exercises
- Splunk Detection Engineering
- Real-world SOC Case Studies
- EDR Alert Investigation
Part of the SOC Analyst path.
The blue-team on-ramp: learn how a modern SOC operates, then build the log-analysis, SIEM, malware, and EDR skills needed to triage and investigate real alerts.
Mentorship & guidance
Need help with a topic or your next career step?
Use mentorship to work through difficult concepts, plan what to study next, and prepare for interviews.
What to know before you enrol.
Who is this SOC analyst training for?
It is designed for learners with basic networking, operating-system, and cybersecurity knowledge, including cybersecurity students, blue-team professionals, security engineers, and incident responders who want deeper investigation practice.
Is the training live or self-paced?
The program includes 35 live online sessions, session recordings, and trainer support. The expected weekly commitment is approximately six hours.
What hands-on SOC skills are covered?
You practise SIEM and Splunk searches, Windows and Sysmon analysis, phishing and malware investigation, EDR triage, detection engineering, incident response, and threat hunting.
Does this SOC course include Splunk training?
Yes. A seven-hour SIEM and Splunk module covers Splunk architecture, log onboarding, SPL searches, dashboards, and alert tuning. You apply those skills in SOC investigation labs.
Does the course include an assessment and certificate?
Yes. An applied assessment and certificate are included. Completion is evaluated through investigation accuracy, evidence handling, detection quality, response decisions, and reporting.
Next step
Is SOC Level 2 Analyst Training right for you?
Ask about the next cohort, course schedule, and whether your experience is a good fit.