Back

SOC Analyst Fundamentals

This course is designed for individuals who are new to cybersecurity and are interested in learning the fundamental skills of a Security Operations Center (SOC) Analyst. A SOC Analyst plays a critical role in an organization's defense against cyber threats, monitoring, detecting, analyzing

Tarek

Lead Trainer

5 hr

Description
Coming soon

Course Curriculum

Introduction

4 lessons

Role of SOC in Cybersecurity

Importance of proactive SOC

SOC team structure and roles

Difference between SOC and other functions

Cyber Attacks Introduction

5 lessons

CIA Triad

Common Cyber Threats

Common Attacks

Understanding TTPs

Understanding IOCs

SOC Lifecycle

4 lessons

SOC lifecycle introduction

Overview of monitoring process

Overview of IR process

Key metrics and KPIs

Key SOC Tools and Technologies

3 lessons

Introduction to essential SOC tools for monitoring

Basic usage of SIEM tools like Splunk or ELK Stack

Using network and host-based intrusion detection systems

Understanding Monitoring

6 lessons

Security monitoring introduction

Security monitoring objectives

Log aggregation and analysis

Monitoring resources (SIEM, EDR, Firewalls, etc.)

Setting up SIEM

SIEM queries, filters and dashboards

Detecting Security Events

4 lessons

Overview of Indicators of Compromise (IOCs)

Analyzing network traffic

Recognizing common attack patterns

Introduction to threat intelligence feeds

Automation in the SOC

3 lessons

Security Orchestration, Automation, and Response (SOAR)

How automation helps SOC analysts

Examples of common SOC automation tasks

Responding to Common Security Incidents

3 lessons

Overview of common incidents

Investigating common attack techniques

How to analyze and assess the impact of a security incident

Investigating Security Alerts

4 lessons

Understanding and prioritizing security alerts in a SOC

Using SIEM tools to investigate security incidents

Correlating data from multiple sources

Distinguishing between false positives and true positives

Best Practices and Building a Strong SOC

5 lessons

Best practices for building and operating a SOC

Developing playbooks and incident response procedures

Ongoing training and skill development for SOC analysts

The importance of collaboration

Effective communication during incidents

Improving SOC Efficiency

3 lessons

How to measure the performance

Key metrics for a successful SOC operation

Continuous improvement