SOC Tier II
Advance into a SOC Level 2 role with hands-on log analysis, advanced SIEM tooling, detection engineering, and threat hunting.
Select your module(s)
You can select the modules you want to learn. There's a recommended order in the learning curve, unless you already know something and want to go further.
Log analysis is collecting, parsing and processing log files and turning data into actionable knowledge to detect security threats and anomalies and identify system performance issues.
- Intro to Logs — Learn the fundamentals of logging, data sources, collection methods and principles to step into the log analysis world.
- Log Operations — Learn the operation process details.
- Intro to Log Analysis — An intro to log analysis, best practices, and essential tools for effective detection and response.
Understand advanced Splunk capabilities to search data for anomalies by creating complex search queries, applying regex, and creating presentable reports and dashboards.
- Splunk: Exploring SPL — Learn and explore the basics of the Search Processing Language.
- Splunk: Setting up a SOC Lab — Explore Splunk beyond basics.
- Splunk: Dashboards and Reports — Creating Dashboards and Reports in Splunk.
- Splunk: Data Manipulation — Learn how to parse and manipulate data in Splunk.
- Fixit — Fix the log parsing issue and analyze the logs in Splunk.
Learn about the main components of the ELK stack by going through the installation and configuring process and linking them together to form an effective log analysis utility.
- Logstash: Data Processing Unit — Learn how to collect, process and transform data with Logstash.
- Custom Alert Rules in Wazuh — Learn how to create rules in Wazuh for your environment.
- Advanced ELK Queries — Search large datasets efficiently with advanced queries in Kibana.
- Slingshot — Can you retrace an attacker's steps after they enumerate and compromise a web server?
Understand various threat detection methodologies, rule syntax and tools, and learn how to apply them in a SOC environment.
- Intro to Detection Engineering — Introduce the concept of detection engineering and the frameworks used towards crafting effective threat detection strategies.
- Tactical Detection — Establish a baseline knowledge of tactical detection, leveraging efficient techniques to bolster your security posture.
- Threat Intelligence for SOC — Learn how to utilise Threat Intelligence to improve the Security Operations pipeline.
- Sigma — Provide understanding to Sigma, a Generic Signature Format for SIEM Systems.
- SigHunt — You are tasked to create detection rules based on a new threat intel.
- Aurora EDR — Familiarise with the use of a Sigma-based EDR tool, Aurora.
- SOAR — Learn the concepts and methodology surrounding security orchestration, automation and response.
Understand the fundamentals of threat hunting, and learn how to build your own methodology for effective hunting across your infrastructure.
- Threat Hunting: Introduction — Behind the scenes of Threat Hunting - mindset, process, and goals.
- Threat Hunting: Foothold — Hunting suspicious activities indicating initial user or host compromise.
- Threat Hunting: Pivoting — Hunting suspicious activities indicating threat propagation across the infrastructure.
- Threat Hunting: Endgame — Learn how to hunt and discover suspicious activities indicating actions on objectives.
- Hunt Me I: Payment Collectors — A Finance Director was recently phished. Can you hunt the logs and determine what damage was done?
- Hunt Me II: Typo Squatters — One of your software developers unknowingly installed a malicious software. Can you trace back the root cause?
Understand the core concepts of threat emulation and learn how to execute adversarial activity through different threat emulation frameworks.
- Intro to Threat Emulation — A look into threat emulation practices as a means of cyber security assessment.
- Threat Modelling — Building cyber resiliency and emulation capabilities through threat modelling.
- Atomic Red Team — Leveraging the Atomic Red Team Framework to strengthen the Security Operations' detection capabilities.
- CALDERA — Leveraging CALDERA to emulate various adversarial activities for detection capability testing.
- Atomic Bird Goes Purple #1 — Time to simulate hunting and detecting activities to sharpen your purple teaming skills.
- Atomic Bird Goes Purple #2 — Time to simulate hunting and detecting activities to sharpen your purple teaming skills.
Understand the mindset behind effective response on security incidents, and apply them through real-world tactics and techniques.
- Preparation — A look into the Preparation phase of the Incident Response.
- Identification & Scoping — A look into the second phase of the Incident Response Framework, Identification & Scoping.
- Threat Intel & Containment — Learn what threat intelligence looks like, and some containment strategies used in the IR process.
- Eradication & Remediation — A look into the fourth phase of the Incident Response framework: Eradication, Remediation, and Recovery.
- Lessons Learned — A look into the fifth phase of the Incident Response framework: Lessons Learned.
- Tardigrade — Can you find all the basic persistence mechanisms in this Linux endpoint?
Explore the world of malware and analyse how malware can infect systems and cause damage.
- x86 Architecture Overview — A crash course in x86 architecture to enable us in malware reverse engineering.
- x86 Assembly Crash Course — A crash course in x86 assembly to enable us in malware reverse engineering.
- Windows Internals — Learn and understand the fundamentals of how Windows operates at its core.
- Dissecting PE Headers — Learn about Portable Executable files and how their headers work.
- Basic Static Analysis — Learn basic malware analysis techniques without running the malware.
- MalBuster — You are tasked to analyse unknown malware samples detected by your SOC team.
- Advanced Static Analysis — Learn how to identify code constructs and examine the assembly code of malware.
- Basic Dynamic Analysis — Learn how to analyze malware Dynamically by running them in a Virtual Machine.
- Dynamic Analysis: Debugging — Learn more advanced techniques of dynamic malware analysis.
- Anti-Reverse Engineering — Learn the techniques used by malware authors to bypass detection.
- MalDoc: Static Analysis — Perform detailed Static Analysis on malicious documents.
Includes Lab practices. All prices are monthly (MXN), before taxes.
Plan your training path
Tell us your team, schedule and modules of interest and we will reply with the next steps.
Request informationOnline enrollment is coming soon. In the meantime, contact us to enroll.
