SOC Analyst & Incident Response Course
Train like a SOC analyst: triage alerts, write detections, hunt threats, investigate incidents and automate response workflows.
Talk to an advisor on WhatsApp
How you will learn
What you will learn, module by module
Detect, investigate and respond to security events using SOC workflows and tooling. Progress from SOC Operations and Alert Triage to SOAR, Metrics and SOC Capstone through guided labs, assessed projects, and portfolio evidence.
01Module 1 · 6 hoursSOC Operations and Alert TriageTriage a queue of simulated alerts and document disposition and escalation decisions.
- SOC tiers
- Incident severity
- Alert lifecycle
- Escalation
- Ticketing
- Evidence
- False positives
- Tools and platforms
- SIEM lab, ticketing template
- Portfolio evidence
- SOC triage workbook
- Assessment
- Triage assessment
02Module 2 · 10 hoursLog Sources and SIEM FundamentalsOnboard sample log sources and create normalized fields/searches.
- Windows/Linux logs
- Authentication
- DNS
- Proxy
- Firewall
- Endpoint
- Cloud logs
- Tools and platforms
- Splunk/Elastic/Microsoft Sentinel lab concepts
- Portfolio evidence
- Log onboarding runbook
- Assessment
- SIEM lab
03Module 3 · 10 hoursDetection Engineering and Threat HuntingCreate and tune detections for credential abuse, persistence and suspicious network activity.
- Detection logic
- Signatures versus behaviour
- Baselines
- MITRE ATT&CK mapping
- Queries
- Tuning
- Hypothesis-driven hunting
- Tools and platforms
- SIEM query language, MITRE ATT&CK
- Portfolio evidence
- Detection rule pack
- Assessment
- Detection review
04Module 4 · 10 hoursEndpoint and Network InvestigationInvestigate a simulated compromise using endpoint and network telemetry.
- Process trees
- Command lines
- Persistence
- Connections
- Packet/log correlation
- EDR concepts
- Timeline building
- Tools and platforms
- EDR lab concepts, Wireshark, SIEM
- Portfolio evidence
- Incident timeline and evidence pack
- Assessment
- Investigation case
05Module 5 · 6 hoursThreat Intelligence and EnrichmentEnrich a set of indicators and convert intelligence into detection/triage actions.
- Indicators
- TTPs
- Intelligence lifecycle
- Confidence
- Feeds
- Enrichment
- Pivoting
- Tools and platforms
- Threat intel sources, ATT&CK
- Portfolio evidence
- Threat intelligence brief
- Assessment
- Intel brief
06Module 6 · 10 hoursIncident Response and Digital EvidenceRun an incident-response scenario and produce containment/recovery actions.
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Evidence handling
- Memory/disk concepts
- Tools and platforms
- IR toolkit concepts, SIEM/EDR lab
- Portfolio evidence
- Incident response report
- Assessment
- IR practical
07Module 7 · 8 hoursPhishing, Malware and Cloud Alert TriageTriage phishing and cloud identity incidents using safe artifacts.
- Email headers
- URLs/domains
- Attachment analysis concepts
- Sandboxing
- Cloud identity alerts
- OAuth abuse concepts
- Suspicious sign-ins
- Tools and platforms
- Email analysis tools, sandbox concepts, cloud logs
- Portfolio evidence
- Phishing/cloud incident case files
- Assessment
- Triage lab
08Module 8 · 16 hoursSOAR, Metrics and SOC CapstoneBuild a simple automated enrichment workflow and complete a multi-stage SOC incident capstone.
- Playbook automation
- Enrichment
- Containment actions
- Human approval
- SOC KPIs
- MTTD/MTTR
- Coverage
- Tools and platforms
- SOAR concepts, SIEM, scripting optional
- Portfolio evidence
- SOC detection and response portfolio
- Assessment
- Capstone and metrics review
Projects you will build
2 portfolio projects plus module evidence
SOC Detection and Response Challenge
Detect and investigate a simulated attack from endpoint/network/cloud logs.
Detection rules · timeline · incident report · response actionsThreat Hunting Detection Pack
Develop ATT&CK-mapped detections and hunt hypotheses for a sample environment.
Query pack · tuning notes · coverage matrix · executive summaryWhy this course
SOC analysts need to interpret telemetry, triage alerts, investigate incidents, document decisions, and improve detections under realistic operational constraints.
The curriculum progresses from SOC Operations and Alert Triage to SOAR, Metrics and SOC Capstone, with guided labs, assessments, and two portfolio projects: SOC Detection and Response Challenge and Threat Hunting Detection Pack.
Who this course is for
Cybersecurity learners and analysts pursuing hands-on SOC, detection and incident response roles.
What you will be able to do
- Triage a queue of simulated alerts and document disposition and escalation decisions.
- Onboard sample log sources and create normalized fields/searches.
- Create and tune detections for credential abuse, persistence and suspicious network activity.
- Investigate a simulated compromise using endpoint and network telemetry.
- Enrich a set of indicators and convert intelligence into detection/triage actions.
- Triage phishing and cloud identity incidents using safe artifacts.
- Build a simple automated enrichment workflow and complete a multi-stage SOC incident capstone.
Technology you will use in this course
Cybersecurity Engineer
This course supports the development of skills relevant to roles such as SOC Analyst, Detection Engineer pathway, and Incident Response Analyst. The strongest learner outcome is a portfolio that shows the problem, implementation, testing or evaluation, documentation and a clear explanation of decisions—not a certificate alone.
Course evidence and instruction
Ranjeet Kumar
Advisor, Brightnest AI Academy · Innovation & Growth LeaderA technologist and data leader with 15+ years of experience applying data, artificial intelligence and machine learning to complex problems, scalable products and business growth.
Learner experience
The SOC project helped me practise alert triage, investigation notes, incident response and the professional reporting expected from analysts.
Industry and technology ecosystem
Clear answers before you enrol
Train like a SOC analyst: triage alerts, write detections, hunt threats, investigate incidents and automate response workflows.
Is the SOC Analyst & Incident Response course suitable for beginners?
This course progresses from intermediate to advanced level. Learners should understand cybersecurity and networking fundamentals and have basic familiarity with Windows/Linux.
What will I build during the course?
You will complete guided labs in every module and build two portfolio projects: SOC Detection and Response Challenge and Threat Hunting Detection Pack. Deliverables include working files or code, documentation, testing or evaluation evidence, and a final presentation.
Which tools and platforms are covered?
Key tools include SIEM lab, ticketing template, Splunk, Elastic, Microsoft Sentinel lab concepts, SIEM query language, MITRE ATT&CK, and EDR lab concepts. Additional platforms are introduced in relevant modules through practical tasks, and the toolset may evolve as industry practice changes.
How long does the course take?
The course includes approximately 76 guided learning hours across 8 modules, normally delivered over 10–12 weeks depending on batch intensity and learner practice time.
Which career paths can this course support?
The curriculum supports the development of skills relevant to roles such as SOC Analyst, Detection Engineer pathway, and Incident Response Analyst. Career outcomes depend on prior experience, project quality, interview readiness and market conditions; employment is not guaranteed.
Will I receive mentor and career support?
The course includes live instruction, lab support, assignment feedback, project reviews and career preparation covering portfolio development, resume writing, LinkedIn profile improvement, and interview guidance.
Ready to start your SOC Analyst & Incident Response journey?
Review the full curriculum, experience a live class and confirm the right starting point before enrolling.
