School of Cybersecurity · Intermediate–Advanced

SOC Analyst & Incident Response Course

Train like a SOC analyst: triage alerts, write detections, hunt threats, investigate incidents and automate response workflows.

Talk to an advisor on WhatsApp
SOC Analyst & Incident Response course illustration at Brightnest AI Academy
SOC Operations and Alert TriageLog Sources and SIEM FundamentalsDetection Engineering and Threat HuntingEndpoint and Network Investigation
SIEM labticketing templateSplunkElasticMicrosoft Sentinel lab concepts
Duration10–12 weeks76 hours
Batch startsConfirm with admissionsOpen for registration
Learning formatLive mentor-led instruction, guided labs, assignments, feedback and project reviewsLive online / classroom
Curriculum8 modulesLabs and assessed capstone
Portfolio2 projectsPlus module evidence
LevelIntermediate–AdvancedCourse level
PathwayCybersecurity EngineerRelated career pathway

How you will learn

Live instructor-led sessions that connect concepts to real workplace decisions.
Guided labs and workshops in every module.
Assignments, checkpoints and practical feedback.
Portfolio documentation, demonstrations and capstone review.
Access to recordings and LMS resources according to the published batch policy.
Career preparation based on completed work and target roles.
Course curriculum

What you will learn, module by module

Detect, investigate and respond to security events using SOC workflows and tooling. Progress from SOC Operations and Alert Triage to SOAR, Metrics and SOC Capstone through guided labs, assessed projects, and portfolio evidence.

01Module 1 · 6 hoursSOC Operations and Alert TriageTriage a queue of simulated alerts and document disposition and escalation decisions.
Topics you will cover
  • SOC tiers
  • Incident severity
  • Alert lifecycle
  • Escalation
  • Ticketing
  • Evidence
  • False positives
Tools and platforms
SIEM lab, ticketing template
Portfolio evidence
SOC triage workbook
Assessment
Triage assessment
02Module 2 · 10 hoursLog Sources and SIEM FundamentalsOnboard sample log sources and create normalized fields/searches.
Topics you will cover
  • Windows/Linux logs
  • Authentication
  • DNS
  • Proxy
  • Firewall
  • Endpoint
  • Cloud logs
Tools and platforms
Splunk/Elastic/Microsoft Sentinel lab concepts
Portfolio evidence
Log onboarding runbook
Assessment
SIEM lab
03Module 3 · 10 hoursDetection Engineering and Threat HuntingCreate and tune detections for credential abuse, persistence and suspicious network activity.
Topics you will cover
  • Detection logic
  • Signatures versus behaviour
  • Baselines
  • MITRE ATT&CK mapping
  • Queries
  • Tuning
  • Hypothesis-driven hunting
Tools and platforms
SIEM query language, MITRE ATT&CK
Portfolio evidence
Detection rule pack
Assessment
Detection review
04Module 4 · 10 hoursEndpoint and Network InvestigationInvestigate a simulated compromise using endpoint and network telemetry.
Topics you will cover
  • Process trees
  • Command lines
  • Persistence
  • Connections
  • Packet/log correlation
  • EDR concepts
  • Timeline building
Tools and platforms
EDR lab concepts, Wireshark, SIEM
Portfolio evidence
Incident timeline and evidence pack
Assessment
Investigation case
05Module 5 · 6 hoursThreat Intelligence and EnrichmentEnrich a set of indicators and convert intelligence into detection/triage actions.
Topics you will cover
  • Indicators
  • TTPs
  • Intelligence lifecycle
  • Confidence
  • Feeds
  • Enrichment
  • Pivoting
Tools and platforms
Threat intel sources, ATT&CK
Portfolio evidence
Threat intelligence brief
Assessment
Intel brief
06Module 6 · 10 hoursIncident Response and Digital EvidenceRun an incident-response scenario and produce containment/recovery actions.
Topics you will cover
  • Preparation
  • Identification
  • Containment
  • Eradication
  • Recovery
  • Evidence handling
  • Memory/disk concepts
Tools and platforms
IR toolkit concepts, SIEM/EDR lab
Portfolio evidence
Incident response report
Assessment
IR practical
07Module 7 · 8 hoursPhishing, Malware and Cloud Alert TriageTriage phishing and cloud identity incidents using safe artifacts.
Topics you will cover
  • Email headers
  • URLs/domains
  • Attachment analysis concepts
  • Sandboxing
  • Cloud identity alerts
  • OAuth abuse concepts
  • Suspicious sign-ins
Tools and platforms
Email analysis tools, sandbox concepts, cloud logs
Portfolio evidence
Phishing/cloud incident case files
Assessment
Triage lab
08Module 8 · 16 hoursSOAR, Metrics and SOC CapstoneBuild a simple automated enrichment workflow and complete a multi-stage SOC incident capstone.
Topics you will cover
  • Playbook automation
  • Enrichment
  • Containment actions
  • Human approval
  • SOC KPIs
  • MTTD/MTTR
  • Coverage
Tools and platforms
SOAR concepts, SIEM, scripting optional
Portfolio evidence
SOC detection and response portfolio
Assessment
Capstone and metrics review
Applied portfolio

Projects you will build

2 portfolio projects plus module evidence

Portfolio project 1

SOC Detection and Response Challenge

Detect and investigate a simulated attack from endpoint/network/cloud logs.

Detection rules · timeline · incident report · response actions
Portfolio project 2

Threat Hunting Detection Pack

Develop ATT&CK-mapped detections and hunt hypotheses for a sample environment.

Query pack · tuning notes · coverage matrix · executive summary
Course value

Why this course

SOC analysts need to interpret telemetry, triage alerts, investigate incidents, document decisions, and improve detections under realistic operational constraints.

The curriculum progresses from SOC Operations and Alert Triage to SOAR, Metrics and SOC Capstone, with guided labs, assessments, and two portfolio projects: SOC Detection and Response Challenge and Threat Hunting Detection Pack.

Course fit

Who this course is for

Cybersecurity learners and analysts pursuing hands-on SOC, detection and incident response roles.

Intermediate–AdvancedCybersecurity Engineer
PrerequisitesLearners should understand cybersecurity and networking fundamentals and have basic familiarity with Windows/Linux.
Practical capabilities

What you will be able to do

  • Triage a queue of simulated alerts and document disposition and escalation decisions.
  • Onboard sample log sources and create normalized fields/searches.
  • Create and tune detections for credential abuse, persistence and suspicious network activity.
  • Investigate a simulated compromise using endpoint and network telemetry.
  • Enrich a set of indicators and convert intelligence into detection/triage actions.
  • Triage phishing and cloud identity incidents using safe artifacts.
  • Build a simple automated enrichment workflow and complete a multi-stage SOC incident capstone.
Tools and platforms

Technology you will use in this course

SIEM labticketing templateSplunkElasticMicrosoft Sentinel lab conceptsSIEM query languageMITRE ATT&CKEDR lab conceptsWiresharkSIEMThreat intel sourcesATT&CKIR toolkit conceptsEDR labEmail analysis toolssandbox concepts
Career relevance

Cybersecurity Engineer

This course supports the development of skills relevant to roles such as SOC Analyst, Detection Engineer pathway, and Incident Response Analyst. The strongest learner outcome is a portfolio that shows the problem, implementation, testing or evaluation, documentation and a clear explanation of decisions—not a certificate alone.

Course evidence and instruction

Academy advisor

Ranjeet Kumar

Advisor, Brightnest AI Academy · Innovation & Growth Leader

A technologist and data leader with 15+ years of experience applying data, artificial intelligence and machine learning to complex problems, scalable products and business growth.

What our learners say

Learner experience

The SOC project helped me practise alert triage, investigation notes, incident response and the professional reporting expected from analysts.
Arjun MehtaCybersecurity Learner · Security Operations Pathway

Industry and technology ecosystem

MicrosoftAmazon Web ServicesDeloitteTech MahindraTata Consultancy ServicesWipro
Course FAQs

Clear answers before you enrol

Train like a SOC analyst: triage alerts, write detections, hunt threats, investigate incidents and automate response workflows.

Is the SOC Analyst & Incident Response course suitable for beginners?

This course progresses from intermediate to advanced level. Learners should understand cybersecurity and networking fundamentals and have basic familiarity with Windows/Linux.

What will I build during the course?

You will complete guided labs in every module and build two portfolio projects: SOC Detection and Response Challenge and Threat Hunting Detection Pack. Deliverables include working files or code, documentation, testing or evaluation evidence, and a final presentation.

Which tools and platforms are covered?

Key tools include SIEM lab, ticketing template, Splunk, Elastic, Microsoft Sentinel lab concepts, SIEM query language, MITRE ATT&CK, and EDR lab concepts. Additional platforms are introduced in relevant modules through practical tasks, and the toolset may evolve as industry practice changes.

How long does the course take?

The course includes approximately 76 guided learning hours across 8 modules, normally delivered over 10–12 weeks depending on batch intensity and learner practice time.

Which career paths can this course support?

The curriculum supports the development of skills relevant to roles such as SOC Analyst, Detection Engineer pathway, and Incident Response Analyst. Career outcomes depend on prior experience, project quality, interview readiness and market conditions; employment is not guaranteed.

Will I receive mentor and career support?

The course includes live instruction, lab support, assignment feedback, project reviews and career preparation covering portfolio development, resume writing, LinkedIn profile improvement, and interview guidance.

Ready to start?

Ready to start your SOC Analyst & Incident Response journey?

Review the full curriculum, experience a live class and confirm the right starting point before enrolling.

A-56, Sector-64, Noida, Uttar Pradesh – 201301