SOC analyst — tiers 1 and 2
For the teams who receive the alerts and have to decide: is this a false positive, an isolated incident, or the beginning of something more serious.
Decide quickly, and know why
An analyst spends most of their time clearing noise. The decisive skill is not knowing the tool, but knowing which question to ask the data and when to escalate.
This programme builds that skill through scenarios replayed in the lab: suspicious authentication, abnormal execution, exfiltration, lateral movement. The datasets are built to reproduce realistic situations without exposing any production data.
Basic systems and networking: what an account, a process, a connection and a log are. No prior SOC experience is needed.
Skills covered
- Read and interpret a security event
- Write a search to test a hypothesis
- Apply a repeatable triage method
- Tell a false positive from a real incident
- Place an observation within the MITRE ATT&CK matrix
- Reconstruct the timeline of an incident
- Apply a tier 1 response procedure
- Write a report a decision-maker can act on
Six modules
| Module | Content | Format |
|---|---|---|
| 1 · Fundamentals | The role of the SOC, tiers 1, 2 and 3, the life cycle of an alert, performance indicators. | Lecture |
| 2 · Reading the data | System, authentication, network, endpoint and cloud logs. What each source tells you, and its blind spots. | Hands-on |
| 3 · Investigation | Search language, filtering, aggregation, manual correlation, pivoting between sources. | Hands-on |
| 4 · Triage | Qualification method, severity criteria, handling false positives, escalation rules. | Workshops on real alerts |
| 5 · MITRE ATT&CK | Tactics and techniques, mapping an alert, reading an attack chain. | Lecture and exercises |
| 6 · Tier 1 response | First-line containment, evidence collection, communication, writing the incident report. | Incident simulation |
The last half-day is given over to a full exercise: an attack chain is replayed in the lab, and participants detect it, qualify it and produce the report. That is where what has genuinely been learned becomes measurable.
Organisation
| Duration | 4 to 5 days, including a half-day simulation |
| Audience | Tier 1 and tier 2 security analysts, technicians moving into SOC work |
| Group size | 4 to 10 participants |
| Environment | A dedicated lab platform, with training datasets |
| Platforms covered | Splunk, Microsoft Sentinel, Elastic Security, OpenText ArcSight, Wazuh |
| Format | On site, remotely in a virtual classroom, or a mix of both |
| Follow-up | Course material kept by participants and a remote consolidation session included |
Bring your team up to speed
We adapt the scenarios to the platform you operate and to the threats relevant to your sector, so the exercises resemble what your analysts will actually meet.