SOC Training
Alert Triage Methodology
SOC Training
0%
Completed
Module 1 — Security Operations Center Foundations
SOC Mission, Functions, and Operating Models
Reading
SOC Tiers and Roles: L1, L2, L3 Analysts
Reading
Security Frameworks: NIST, MITRE ATT&CK, Cyber Kill Chain
Reading
Threat Actors, TTPs, SOC Metrics, and Maturity Models
Reading
Module 2 — Network and Endpoint Security Monitoring
Network Protocols and Traffic Analysis
Reading
Packet Capture and Analysis with Wireshark
Reading
Endpoint Detection and Response Concepts
Reading
Sysmon, Windows Event Logs, Linux Logs, and Log Normalization
Reading
Module 3 — SIEM Architecture and Use Cases
SIEM Architecture and Data Ingestion
Reading
Log Sources, Parsers, and Normalization
Reading
Correlation Rules and Alert Logic
Reading
Use Case Development, Splunk, Sentinel, and QRadar Basics
Reading
Module 4 — Threat Detection and Alert Triage
Alert Triage Methodology
Reading
False Positive Reduction Techniques
Reading
IOC and IOA Analysis
Reading
Memory and Disk Forensics Introduction, Threat Hunting Basics
Reading
Module 5 — Incident Response and Handling
Incident Response Lifecycle: Preparation, Detection, Containment
Reading
Incident Categorization and Prioritization
Reading
Evidence Handling and Chain of Custody
Reading
Containment, Eradication, Recovery, and Post-Incident Reporting
Reading
Module 6 — Malware Analysis Fundamentals
Malware Types and Behaviors
Reading
Static Analysis Techniques and Tools
Reading
Dynamic Analysis in Sandbox Environments
Reading
YARA Rules, Signature Creation, and Reverse Engineering Basics
Reading
Module 7 — Threat Intelligence and Hunting
Threat Intelligence Types: Strategic, Tactical, Operational
Reading
TI Platforms and Feeds
Reading
Threat Hunting Hypotheses and Methodologies
Reading
MITRE ATT&CK Mapping and Intelligence-Driven Detection
Reading
Module 8 — Cloud Security Monitoring
Cloud Security Challenges and Shared Responsibility
Reading
AWS, Azure, and GCP Logging and Monitoring
Reading
Cloud SIEM and Native Security Tools
Reading
Container and Kubernetes Security Monitoring and Threat Detection
Reading
Module 9 — Phishing and Email Security
Email Threats: Phishing, Spear Phishing, BEC
Reading
Email Headers and Trace Analysis
Reading
Email Security Gateway Investigation
Reading
User Awareness, Reporting Workflows, and Phishing Incident Response
Reading
Module 10 — Digital Forensics Basics
Forensic Principles and Legal Considerations
Reading
Disk Imaging and File System Analysis
Reading
Memory Forensics and Artifacts
Reading
Timeline Analysis, Correlation, and Forensic Reporting
Reading
Module 11 — SOC Automation and Orchestration
SOAR Platforms and Playbooks
Reading
Automation Use Cases in SOC
Reading
API Integrations for Enrichment
Reading
Case Management, Workflow Automation, and Continuous Improvement
Reading
Module 12 — Real-World Projects and Interview Preparation
SOC Alert Triage Simulation
Reading
Incident Response Tabletop Exercise
Reading
Threat Hunting Campaign Project
Reading
SOC Analyst Interview Questions, Resume, and LinkedIn Optimization
Reading
More
Announcements
Course Info