SOC Analyst, Tier 1-2
Associate-level course
A course that trains a SOC analyst to work the SIEM on Splunk - reading alerts, triaging and enriching them, and handling an incident from the first sign to closure. Graduates can tell a real incident from a false positive, investigate it and pass it on to Tier 2, and sit prepared for the Splunk, CompTIA and Microsoft SOC certification exams.
- Registration
- Waiting list
- Duration
- 48 academic hours
- Format
- In personHybrid
- Level
- Associate
- Certification
- SpotAcademy certificate of completion
- Language
- Hebrew, course materials in English
- For organisations
- By arrangement - at the academy or hybrid
What you will be able to do
- Monitor and triage alerts in Splunk Enterprise Security, confirming or adjusting each alert's criticality.
- Separate a genuine incident from a false positive and enrich it with context before acting.
- Write and run SPL searches, and build reports, alerts and dashboards over live log data.
- Investigate a notable through the analyst queue and document the timeline of an attack.
- Map an incident to MITRE ATT&CK tactics and techniques and to the NIST incident response life cycle.
- Hand an incident to Tier 2 with the scope, affected systems and evidence a responder needs.
The syllabus
8 modules over 48 academic hours. Open a module for its topics.
- The NIST CSF 2.0 Functions - Govern, Identify, Protect, Detect, Respond, Recover
- The NIST SP 800-61 incident response life cycle
- MITRE ATT&CK tactics and techniques
- How a SOC is organised - the Analyst, Engineer and Architect roles
- Attack vectors and indicators of compromise
- The kill chain
- Alert monitoring, triage and false-positive handling
- Enrichment, criticality and documented playbooks
- Passing an incident on to Tier 2
- Intro to Splunk - indexes, events and getting data in
- Searching with SPL and using fields
- Reports, alerts and scheduled searches
- Dashboards and visualisations
- Working with time and statistical processing
- Log sources and getting data in
- The Common Information Model (CIM)
- Lookups and subsearches
- Knowledge objects and field extractions
- Data models
- Notables and findings
- The analyst queue and investigations
- Risk-based alerting
- Correlation searches
- Adaptive response actions
- Scoping an incident and its affected systems
- Enrichment with threat intelligence
- Containment, eradication and recovery
- Case management and handover
- Reporting
- Hypothesis-driven hunts in SPL
- Mapping detections to MITRE ATT&CK
- Tuning detections against false positives
- An introduction to KQL for Microsoft Sentinel
- A blue-team, capture-the-flag style investigation on the Boss of the SOC dataset
- An APT scenario and a ransomware scenario
- Mapping the evidence to the kill chain
- An exam-mapping session for the Splunk, CompTIA and Microsoft exams
Who it is for
Who takes this course, and what you need before the first session.
Help-desk and IT people moving into security operations.
Junior analysts who want to work a SIEM to a Tier 1-2 standard.
Teams standing up or staffing a security operations centre.
Prerequisites
The course assumes basic familiarity with networking and with the Windows and Linux operating systems; no prior SOC experience is required.
The exam and the certification
The course prepares for several recognised certification exams in this field: Splunk Certified Cybersecurity Defense Analyst (66 questions, 75 minutes), CompTIA CySA+ in the CS0-004 version, and Microsoft SC-200 over Microsoft Defender XDR and Microsoft Sentinel. Anyone coming from a networking background can add Cisco CCNA Cybersecurity (exam 200-201 CCNACBR). The exams are sat in English through Pearson VUE, and each carries the vendor's own validity period; registration and payment are handled with the vendor directly.
The certification
SpotAcademy certificate of completion
Splunk
Splunk Certified Cybersecurity Defense Analyst: 66 questions, 75 minutes, through Pearson VUE. No prerequisite certification; Splunk recommends Power User level knowledge.
CompTIA and Microsoft
CompTIA CySA+ (CS0-004): up to 85 questions, 165 minutes, on a three-year renewal cycle. Microsoft SC-200: 100 minutes, renewed every twelve months with a free online assessment.
Cisco
Cisco CCNA Cybersecurity (200-201 CCNACBR): 120 minutes, no prerequisites, valid three years. The Splunk, CompTIA and Cisco exams are booked through Pearson VUE.
The labs
The work runs in the lab's Splunk environment, fed with logs from Windows and Linux servers and from network traffic. Participants write SPL searches, build dashboards and alerts, work notables through the analyst queue, and investigate a full incident on the Boss of the SOC dataset, from the first sign to the closing report.
Two ways to take the course
The waiting list for the next open cohort, or an intensive format for a team - which a team can have on its own dates, whatever the open cohorts are doing.
The next cohort
The next cohort is in planning - 48 academic hours at the academy in Shoham. A hybrid option is available, with part of the sessions remote. Join the waiting list and you hear the dates first; the list is also what decides which course opens next.
For your team
An intensive format, by arrangement - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.
Related courses
Fortinet security operations (NSE 5-6)
Preparation for the NSE 5 and NSE 6 certifications in Security Operations, on the three platforms a Fortinet SOC runs on - the FortiAnalyzer, FortiSIEM and FortiSOAR platforms. Participants leave able to collect and analyse the logs, work an incident from event to closure, and build the playbooks that run the routine automatically.
Explore Professional Opening soonPenetration Testing
A penetration-testing course that opens with methodology and moves to the tools - Nmap, Burp Suite, Metasploit and the OWASP Top 10 - against targets built for the purpose in the lab. Graduates can plan an engagement, gather intelligence, exploit a weakness, escalate privileges and move laterally across an Active Directory domain, and write a report a client can act on.
Explore