Skip to main content
← All training programs
Intermediate to AdvancedHands-on labs

Instructor-led training · Hands-on practice

SOC Level 2 Analyst Training

Investigate alerts using SIEM, endpoint, identity, email, and network evidence, then decide how to respond.

Course at a glance

Learn to investigate security alerts and decide what to do next.

LevelIntermediate to Advanced
Duration30–35 Hours
FormatOnline — instructor-led with recordings
6Modules
6Core tools
Live classes35 live sessions
RecordingsRecordings included
Trainer supportTrainer support included
AssessmentAssessment and certificate included
Weekly commitment6 hours per week
Program overview

Learn how a SOC investigation works, from alert to response.

This instructor-led, intermediate-to-advanced course teaches you to investigate alerts, analyse logs and malware, search SIEM data, and use endpoint evidence. Guided labs follow realistic attack scenarios—from initial triage and scope to detection and response decisions.

Core focus

SOC OperationsSIEM & SplunkMalware AnalysisEDR InvestigationDetection EngineeringThreat Hunting
Course fit

Is this training right for you?

Check the background expected before you explore the full curriculum.

Who it’s for

  • Security Engineers
  • Incident Responders
  • Blue Team professionals
  • Cybersecurity students

What you should know first

  • Basic understanding of networking, operating systems, and cybersecurity concepts
  • Familiarity with common attack types and security controls
  • Some exposure to logs, command-line tools, or SOC workflows is helpful

How you’ll practise

  • SOC Analyst interview questions
  • MCQs & quizzes
  • Real-world investigation scenarios
  • Detection challenges
  • Hands-on assignments
  • Incident-investigation exercise
SOC analyst training online

Practise a complete SOC investigation.

Learn how to move from an alert to a conclusion you can support with evidence.

Search Splunk and other SIEM data alongside Windows Event Logs, Sysmon, endpoint activity, email evidence, and network traffic. You’ll validate an alert, work out what was affected, and build a timeline of what happened.

Guided labs cover phishing, malware, EDR alerts, detection engineering, and threat hunting. Assessments look at the evidence you collect, the decisions you make, and how clearly you report your findings.

What you’ll learn

Skills you’ll practise in this course.

Each outcome is tied to practical investigation or engineering work.

  • Investigate and triage SOC alerts effectively
  • Perform advanced log analysis across Windows, Linux, and network sources
  • Analyze Windows Event Logs and Sysmon events for malicious activity
  • Detect malicious behavior using SIEM (Splunk) and EDR platforms
  • Conduct full malware investigations using static and dynamic techniques
  • Build custom detections, dashboards, and correlation rules
  • Investigate phishing campaigns and web-based attacks
  • Perform structured threat hunting using multiple methodologies
  • Handle real-world SOC incidents confidently, end-to-end
SIEM & Splunk operations

Splunk training within SOC Level 2.

The seven-hour SIEM and Splunk module is part of this SOC analyst course, not a separate standalone course.

See the full SOC curriculum →

Start with the path security data takes into a SIEM. Then use Splunk Search Processing Language (SPL) to find events, narrow results, and connect activity across Windows and Sysmon logs. You’ll also work with dashboards, alert creation, and tuning.

For example, you might search for repeated failed logins, find a later successful login, and check the same host for unusual process activity. The goal is to explain what the evidence supports—not just return a matching event.

Tools and methods

Tools you’ll work with.

See the platforms and methods used throughout the lessons and labs.

Splunk Enterprise
SIEM
Sysmon
Endpoint Telemetry
Wireshark
Network Analysis
VirusTotal
Threat Intel
ANY.RUN
Malware Sandbox
Microsoft Defender for Endpoint
EDR/XDR
Your work

What you’ll produce.

Build practical work you can discuss and explain, not just a record of attendance.

  • SOC alert triage and escalation record
  • Windows and Sysmon investigation timeline
  • SPL detection query with tuning notes
  • Phishing-analysis report
  • Malware sandbox investigation summary
  • Endpoint compromise case report

Assessment standards

Completion is based on applied work, not attendance alone.

  • Accuracy of alert triage and prioritization
  • Quality of evidence collection and investigation pivots
  • Clarity of scope, impact, and containment recommendations
  • Detection logic quality and false-positive awareness
  • Completeness of the final investigation report

Safe lab conduct

Exercises remain inside authorized, isolated training environments.

  • Use only the isolated training environment and authorized datasets
  • Never upload confidential or production data to public analysis services
  • Keep malware samples and simulations inside the designated lab workflow
  • Document investigation steps and restore or clean up the lab after each exercise
Curriculum

Explore the 6 course modules.

Open a module to see its topics and hands-on exercises.

  • SOC architecture and workflow
  • Roles and responsibilities of SOC analysts
  • SOC metrics and SLAs
  • Alert lifecycle management
  • CIA Triad
  • Defense in Depth
  • Common security controls
  • Attack vectors
  • Cyber Kill Chain
  • MITRE ATT&CK deep dive
  • NIST & CIS Controls
  • SIEM, EDR/XDR, IDS/IPS, Firewalls
  • Ransomware, phishing & credential attacks

Practical labs

Put the lessons into practice.

Use lab evidence and security tools to work through investigation and response decisions.

Investigation labs

  • Windows Event Log Analysis
  • Threat Hunting Labs
  • Sysmon Investigation
  • Phishing Investigation
  • Malware Sandbox Analysis
  • Adversary Simulation Exercises
  • Splunk Detection Engineering
  • Real-world SOC Case Studies
  • EDR Alert Investigation
Learning path

Part of the SOC Analyst path.

The blue-team on-ramp: learn how a modern SOC operates, then build the log-analysis, SIEM, malware, and EDR skills needed to triage and investigate real alerts.

SOC FundamentalsLog AnalysisSIEM & SplunkMalware AnalysisEDRIncident InvestigationThreat HuntingInterview Preparation
Explore full interactive roadmap →

Mentorship & guidance

Need help with a topic or your next career step?

Use mentorship to work through difficult concepts, plan what to study next, and prepare for interviews.

Enquire about mentorship
Common questions

What to know before you enrol.

Who is this SOC analyst training for?

It is designed for learners with basic networking, operating-system, and cybersecurity knowledge, including cybersecurity students, blue-team professionals, security engineers, and incident responders who want deeper investigation practice.

Is the training live or self-paced?

The program includes 35 live online sessions, session recordings, and trainer support. The expected weekly commitment is approximately six hours.

What hands-on SOC skills are covered?

You practise SIEM and Splunk searches, Windows and Sysmon analysis, phishing and malware investigation, EDR triage, detection engineering, incident response, and threat hunting.

Does this SOC course include Splunk training?

Yes. A seven-hour SIEM and Splunk module covers Splunk architecture, log onboarding, SPL searches, dashboards, and alert tuning. You apply those skills in SOC investigation labs.

Does the course include an assessment and certificate?

Yes. An applied assessment and certificate are included. Completion is evaluated through investigation accuracy, evidence handling, detection quality, response decisions, and reporting.

Next step

Is SOC Level 2 Analyst Training right for you?

Ask about the next cohort, course schedule, and whether your experience is a good fit.