COURSE ID: SEC-SOC-02

Security Operations Center (SOC) Operations / Blue Teaming

Master real-time threat monitoring, alert triage, and enterprise defense under the guidance of a seasoned industry leader.

Format

Live Online Batches

Duration

6-Week Intensive

Audience

Graduates & Career Changers

Skills You Will Gain

SIEM Management Log Normalization Endpoint Detection & Response (EDR) Alert Triage Blue Teaming Threat Detection Network Security Monitoring Packet Analysis Incident Containment Threat Intel Ingestion Log Parsing (RegEx) SOAR Automation Mitre ATT&CK Mapping Windows/Linux Security Logs Behavioral Baseline Analysis Phishing Analysis Continuous Monitoring SOC Playbooks Attack Lifecycle Verification Agentic AI Workflows

What You Will Master

Become a highly capable defender in this hands-on, intensive operations program. From establishing continuous logging architectures and querying SIEM big data to hunting persistent threats using EDR telemetry and crafting SOAR containment playbooks, you will develop true blue-team intuition. Capstone simulations guarantee you are fully equipped to navigate live production pipelines, manage alerts under pressure, and reduce mean-time-to-detection. Transform your technical foundation into specialized operational readiness.

  • Deploy, tune, and query industry-standard SIEM environments to isolate indicators of compromise (IoCs).
  • Analyze enterprise log streams across Windows Event Logs, Syslog, and cloud-native telemetry.
  • Isolate, triage, and contain live malicious activity across host environments utilizing advanced EDR solutions.
  • Design structured SOC playbooks that cleanly map enterprise threat profiles to the MITRE ATT&CK framework.
  • Understand how Agentic AI engines can be deployed to automatically normalize logs, enrich alerts, and accelerate defensive triage pipelines.

The Curriculum Journey (4 Modules)

01
Telemetry Foundations & SIEM Architecture: Build the bedrock of visibility. Learn log normalization, collection strategies, and correlation rules. Master big data query structures to parse through raw enterprise noise and extract high-fidelity alerts.
02
Host Defense & Endpoint Telemetry: Dive deep into system-level auditing. Analyze live Windows and Linux event tracking systems, run simulated endpoint compromises, and use enterprise EDR dashboards to identify malicious persistence and privilege escalation.
03
Network Visibility & Triage Playbooks: Unpack the network layer. Combine wire-level packet captures with centralized firewalls and proxy logs. Translate discoveries into standard operating playbooks that systematically map to real-world adversary behavior.
04
Automated Containment, AI Agents & Capstone: Scale your defense. Explore SOAR principles and design Agentic AI enrichment pipelines to automate alert triage. Conclude with a high-stakes, live-fire SOC simulation to identify, isolate, and contain an active attack.