SOC Level 1

Price
$2,499.00 USD

Duration
4 Days

 

Delivery Methods
Virtual Instructor Led
Private Group

Course Overview

Take your SOC analyst skills to the next level in this live training presented by Andrew Prince. You’ll hit the ground running with four full days of back-to-back live training, labs, and challenges that cover the foundational skills needed for success in defensive security operations.

This training dives deep into monitoring, detection, analysis, and response across critical areas including phishing, network security, endpoint protection, SIEM management, threat intelligence, and DFIR operations.

By the end of this training, you’ll have an in-depth grasp of SOC operations and investigative skills. All lessons draw from real-world SOC experience and scenarios encountered by security professionals in active environments. This class is limited to 50 students, so sign up today to reserve your spot.

Course Objectives

  • Security Operations Fundamentals
  • Phishing Analysis
  • Network Security Monitoring
  • Network Traffic Analysis
  • Endpoint Security Monitoring
  • Endpoint Detection and Response
  • Log Analysis and Management
  • Security Information and Event Management (SIEM)
  • Threat Intelligence
  • Digital Forensics
  • Incident Response

Who Should Attend?

  • Aspiring SOC Analysts and Incident Responders.
  • Individuals with a strong interest in blue teaming and a desire to understand how security operations work in real-world environments.
  • IT professionals with some experience in networking or systems administration who want to expand their skills into the SOC and cybersecurity field.
  • Students looking to prepare for the Practical SOC Analyst Associate (PSAA) exam.
  • Top-rated instructors: Our crew of subject matter experts have an average instructor rating of 4.8 out of 5 across thousands of reviews.
  • Authorized content: We maintain more than 35 Authorized Training Partnerships with the top players in tech, ensuring your course materials contain the most relevant and up-to date information.
  • Interactive classroom participation: Our virtual training includes live lectures, demonstrations and virtual labs that allow you to participate in discussions with your instructor and fellow classmates to get real-time feedback.
  • Post Class Resources: Review your class content, catch up on any material you may have missed or perfect your new skills with access to resources after your course is complete.
  • Private Group Training: Let our world-class instructors deliver exclusive training courses just for your employees. Our private group training is designed to promote your team’s shared growth and skill development.
  • Tailored Training Solutions: Our subject matter experts can customize the class to specifically address the unique goals of your team.

Course Prerequisites

System Requirements

  • 8GB RAM & 256GB HDD
  • Up-to-Date OS & Internet Browser
  • Stable Internet connection

Completion of the Practical Help Desk course, A+/Net+ equivalent, or familiarity with the topics such as:

  • Basic familiarity with Windows and Linux operating system components.
  • Experience working with the command-line and knowledge of basic commands and navigation (e.g., cd, ls, cat).
  • Knowledge of network concepts such as subnets, internal vs. external IP addresses, network address translation, and routing.
  • Understanding of foundational security concepts such as the CIA triad, security controls, encryption, and hashing.

Agenda

Day 1

  • Class Introduction
  • Lab Access, Setup, and Configuration
  • Understanding the SOC
  • Understanding Phishing Attacks and Techniques
  • Email Analysis
  • URL Analysis
  • Attachment Analysis
  • MalDoc Analysis
  • Phishing Defenses
  • Ticket Challenge – Walkthrough and Break
  • Understanding Packets and Flows
  • Network Traffic Analysis with TCPDump
  • Network Traffic Analysis with Wireshark
  • Ticket Challenge

Day 2

  • Understanding Endpoint Security
  • Windows – Hunting Malicious Network Connections
  • Windows – Hunting Malicious Processes
  • Live IR with SysInternals and Autoruns
  • Windows – Understanding Core Processes
  • Windows – Hunting Persistence
  • Ticket Challenge – Walkthrough and Break
  • Linux – Hunting Malicious Network Connections
  • Linux – Hunting Malicious Processes
  • Linux – Understanding Core Processes
  • Linux – Hunting Persistence
  • Ticket Challenge – Walkthrough and Break
  • Understanding the SIEM
  • Common Attack Signatures
  • Command Line Log Analysis
  • Ticket Challenge

Day 3

  • Splunk Introduction
  • Search Processing Language
  • Search Commands
  • Reporting, Alerting, and Dashboards
  • Investigating Intrusions with Splunk
  • Deploying Forwarders
  • Ticket Challenge – Walkthrough and Break
  • Understanding Threat Intelligence
  • Threat Intelligence Frameworks
  • MITRE ATT&CK
  • Ticket Challenge – Walkthrough and Break
  • Detecting Malware with YARA
  • Reading and Writing YARA Rules
  • Ticket Challenge

Day 4

  • Understanding Digital Forensics Investigations
  • Disk Image Acquisition with FTK Imager
  • Memory Acquisition with FTK Imager
  • Ticket Challenge – Walkthrough and Break
  • Windows Forensic Artifacts
  • Forensic Image Analysis with Autopsy
  • Memory Analysis with Volatility
  • Ticket Challenge – Walkthrough and Break
  • The Incident Response Process
  • Training Wrap-Up
 

Upcoming Class Dates and Times

Jul 21-24
9:00 AM - 5:00 PM
ENROLL $2,499.00 USD
Sept 15-18
9:00 AM - 5:00 PM
ENROLL $2,499.00 USD
Nov 17-20
9:00 AM - 5:00 PM
ENROLL $2,499.00 USD
 



Do You Have Additional Questions? Please Contact Us Below.

contact us contact us 
Contact Us about Starting Your Business Training Strategy with New Horizons