Home About For organisations The labs Gallery FAQ Contact

SOC Analyst, Tier 1-2
Associate-level course

A course that trains a SOC analyst to work the SIEM on Splunk - reading alerts, triaging and enriching them, and handling an incident from the first sign to closure. Graduates can tell a real incident from a false positive, investigate it and pass it on to Tier 2, and sit prepared for the Splunk, CompTIA and Microsoft SOC certification exams.

Registration
Waiting list
Duration
48 academic hours
Format
In personHybrid
Level
Associate
Certification
SpotAcademy certificate of completion
Language
Hebrew, course materials in English
For organisations
By arrangement - at the academy or hybrid

What you will be able to do

  • Monitor and triage alerts in Splunk Enterprise Security, confirming or adjusting each alert's criticality.
  • Separate a genuine incident from a false positive and enrich it with context before acting.
  • Write and run SPL searches, and build reports, alerts and dashboards over live log data.
  • Investigate a notable through the analyst queue and document the timeline of an attack.
  • Map an incident to MITRE ATT&CK tactics and techniques and to the NIST incident response life cycle.
  • Hand an incident to Tier 2 with the scope, affected systems and evidence a responder needs.

The syllabus

8 modules over 48 academic hours. Open a module for its topics.

  • The NIST CSF 2.0 Functions - Govern, Identify, Protect, Detect, Respond, Recover
  • The NIST SP 800-61 incident response life cycle
  • MITRE ATT&CK tactics and techniques
  • How a SOC is organised - the Analyst, Engineer and Architect roles

  • Attack vectors and indicators of compromise
  • The kill chain
  • Alert monitoring, triage and false-positive handling
  • Enrichment, criticality and documented playbooks
  • Passing an incident on to Tier 2

  • Intro to Splunk - indexes, events and getting data in
  • Searching with SPL and using fields
  • Reports, alerts and scheduled searches
  • Dashboards and visualisations
  • Working with time and statistical processing

  • Log sources and getting data in
  • The Common Information Model (CIM)
  • Lookups and subsearches
  • Knowledge objects and field extractions
  • Data models

  • Notables and findings
  • The analyst queue and investigations
  • Risk-based alerting
  • Correlation searches
  • Adaptive response actions

  • Scoping an incident and its affected systems
  • Enrichment with threat intelligence
  • Containment, eradication and recovery
  • Case management and handover
  • Reporting

  • Hypothesis-driven hunts in SPL
  • Mapping detections to MITRE ATT&CK
  • Tuning detections against false positives
  • An introduction to KQL for Microsoft Sentinel

  • A blue-team, capture-the-flag style investigation on the Boss of the SOC dataset
  • An APT scenario and a ransomware scenario
  • Mapping the evidence to the kill chain
  • An exam-mapping session for the Splunk, CompTIA and Microsoft exams
SOC Analyst, Tier 1-2 Opening soon +972 8-669-8400

Who it is for

Who takes this course, and what you need before the first session.

Help-desk and IT people moving into security operations.

Junior analysts who want to work a SIEM to a Tier 1-2 standard.

Teams standing up or staffing a security operations centre.

Prerequisites

The course assumes basic familiarity with networking and with the Windows and Linux operating systems; no prior SOC experience is required.

The exam and the certification

The course prepares for several recognised certification exams in this field: Splunk Certified Cybersecurity Defense Analyst (66 questions, 75 minutes), CompTIA CySA+ in the CS0-004 version, and Microsoft SC-200 over Microsoft Defender XDR and Microsoft Sentinel. Anyone coming from a networking background can add Cisco CCNA Cybersecurity (exam 200-201 CCNACBR). The exams are sat in English through Pearson VUE, and each carries the vendor's own validity period; registration and payment are handled with the vendor directly.

SpotAcademy certificate of completion

The certification

SpotAcademy certificate of completion

Splunk

Splunk Certified Cybersecurity Defense Analyst: 66 questions, 75 minutes, through Pearson VUE. No prerequisite certification; Splunk recommends Power User level knowledge.

CompTIA and Microsoft

CompTIA CySA+ (CS0-004): up to 85 questions, 165 minutes, on a three-year renewal cycle. Microsoft SC-200: 100 minutes, renewed every twelve months with a free online assessment.

Cisco

Cisco CCNA Cybersecurity (200-201 CCNACBR): 120 minutes, no prerequisites, valid three years. The Splunk, CompTIA and Cisco exams are booked through Pearson VUE.

The labs

The work runs in the lab's Splunk environment, fed with logs from Windows and Linux servers and from network traffic. Participants write SPL searches, build dashboards and alerts, work notables through the analyst queue, and investigate a full incident on the Boss of the SOC dataset, from the first sign to the closing report.

The SpotAcademy classroom in Shoham - rows of workstations, and the equipment rack behind them
The classroom in Shoham. The sessions run here, and the lab environment is reached from the workstations and from home.

Two ways to take the course

The waiting list for the next open cohort, or an intensive format for a team - which a team can have on its own dates, whatever the open cohorts are doing.

The next cohort

The next cohort is in planning - 48 academic hours at the academy in Shoham. A hybrid option is available, with part of the sessions remote. Join the waiting list and you hear the dates first; the list is also what decides which course opens next.

For your team

An intensive format, by arrangement - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.

Leave us your details

A few lines about what you are after - a course for yourself or training for a team - are enough. The message reaches the academy team directly.

Who is this for