← Back to the catalogueSOC Analyst
Beginner to Advanced
Level
Classroom . Online . Hybrid
Mode
Course overview
A security operations centre course built around alert triage, investigation and escalation. Learners work as a tier-one analyst would: reading logs, triaging alerts ina SIEM, mapping activity to MITRE ATT&CK, deciding what to escalate and writing the case notes that follow it.
The course runs on Splunk and Wazuh with simulated attack data, and closes with a timed incident simulation.
Who it is for
- Graduates entering security operations
- IT support staff moving to security
- Network administrators on shift teams
- Analysts preparing for blue team roles
Prerequisites
Basic networking, Windows and Linux familiarity.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Timed Incident Simulation and Report
Programme sheet
The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.
Learning outcomes
01
Read and correlate Windows, Linux and network logs.
02
Investigate with a SIEM and document findings.
03
Write detection rules and tune false positives.
04
Escalate with a clear, evidenced handover.
05
Triage alerts by severity and business impact.
06
Map observed behaviour to MITRE ATT&CK techniques.
07
Follow an incident response playbook.
Module structure
8 modulesSOC tiers and roles . Ticketing . Escalation paths . Shift handover . SLAs . Documentation standards
Windows event logs . Linux auditd . DNS logs . Sysmon . Firewall and proxy logs
Lab
Log Walkthrough . Cloud Logs
Module 03
SIEM Fundamentals
Ingestion and parsing . Normalisation . Search queries . Dashboards
Tools — Splunk, Wazuh, ELK Stack
Alert anatomy . Enrichment . True vs false positive . Priority matrix
Module 05
Threat Frameworks
MITRE ATT&CK . Tactics and techniques . Gap analysis . Kill chain . Detection coverage mapping
Module 06
Detection Engineering
Rule writing . Thresholds and baselines . Testing detections . Sigma rules . Tuning
Module 07
Threat Intelligence
IOCs and IOAs . Reputation lookups . Malware triage basics . Feeds . Phishing analysis
Tools — ISP
Module 08
Incident Response
Playbooks . Forensic capture . Reporting . Lessons learned
Project — Containment Decisions, Communication
Assessment & certification
Module assignments and labs
25%
Final project and review
40%
Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.
Career outcomes . Roles this programme prepares for
SOC Analyst (tier 1/2)Security Operations EngineerIncident Response AnalystThreat Detection EngineerCyber Security Analyst