Under attack?
Security analyst programme

SOC analyst — tiers 1 and 2

For the teams who receive the alerts and have to decide: is this a false positive, an isolated incident, or the beginning of something more serious.

  • 4 to 5 days
  • Security analysts
  • MITRE ATT&CK
  • Dedicated lab
Who this programme is for

Decide quickly, and know why

An analyst spends most of their time clearing noise. The decisive skill is not knowing the tool, but knowing which question to ask the data and when to escalate.

This programme builds that skill through scenarios replayed in the lab: suspicious authentication, abnormal execution, exfiltration, lateral movement. The datasets are built to reproduce realistic situations without exposing any production data.

Prerequisites

Basic systems and networking: what an account, a process, a connection and a log are. No prior SOC experience is needed.

Skills covered

  • Read and interpret a security event
  • Write a search to test a hypothesis
  • Apply a repeatable triage method
  • Tell a false positive from a real incident
  • Place an observation within the MITRE ATT&CK matrix
  • Reconstruct the timeline of an incident
  • Apply a tier 1 response procedure
  • Write a report a decision-maker can act on
Syllabus

Six modules

ModuleContentFormat
1 · FundamentalsThe role of the SOC, tiers 1, 2 and 3, the life cycle of an alert, performance indicators.Lecture
2 · Reading the dataSystem, authentication, network, endpoint and cloud logs. What each source tells you, and its blind spots.Hands-on
3 · InvestigationSearch language, filtering, aggregation, manual correlation, pivoting between sources.Hands-on
4 · TriageQualification method, severity criteria, handling false positives, escalation rules.Workshops on real alerts
5 · MITRE ATT&CKTactics and techniques, mapping an alert, reading an attack chain.Lecture and exercises
6 · Tier 1 responseFirst-line containment, evidence collection, communication, writing the incident report.Incident simulation
Final simulation

The last half-day is given over to a full exercise: an attack chain is replayed in the lab, and participants detect it, qualify it and produce the report. That is where what has genuinely been learned becomes measurable.

Practical information

Organisation

Duration4 to 5 days, including a half-day simulation
AudienceTier 1 and tier 2 security analysts, technicians moving into SOC work
Group size4 to 10 participants
EnvironmentA dedicated lab platform, with training datasets
Platforms coveredSplunk, Microsoft Sentinel, Elastic Security, OpenText ArcSight, Wazuh
FormatOn site, remotely in a virtual classroom, or a mix of both
Follow-upCourse material kept by participants and a remote consolidation session included

Bring your team up to speed

We adapt the scenarios to the platform you operate and to the threats relevant to your sector, so the exercises resemble what your analysts will actually meet.