← Back to the catalogue
Domain 05 . Security

SOC Analyst

60
Hours of teaching
Beginner to Advanced
Level
8
Modules
Classroom . Online . Hybrid
Mode
Course overview

A security operations centre course built around alert triage, investigation and escalation. Learners work as a tier-one analyst would: reading logs, triaging alerts ina SIEM, mapping activity to MITRE ATT&CK, deciding what to escalate and writing the case notes that follow it.

The course runs on Splunk and Wazuh with simulated attack data, and closes with a timed incident simulation.

Who it is for
  • Graduates entering security operations
  • IT support staff moving to security
  • Network administrators on shift teams
  • Analysts preparing for blue team roles
Prerequisites
Basic networking, Windows and Linux familiarity.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Timed Incident Simulation and Report

Programme sheet

The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.

Learning outcomes

01
Read and correlate Windows, Linux and network logs.
02
Investigate with a SIEM and document findings.
03
Write detection rules and tune false positives.
04
Escalate with a clear, evidenced handover.
05
Triage alerts by severity and business impact.
06
Map observed behaviour to MITRE ATT&CK techniques.
07
Follow an incident response playbook.

Module structure

8 modules
Module 01

SOC Operations

SOC tiers and roles . Ticketing . Escalation paths . Shift handover . SLAs . Documentation standards
Module 02

Log Sources

Windows event logs . Linux auditd . DNS logs . Sysmon . Firewall and proxy logs
Lab
Log Walkthrough . Cloud Logs
Module 03

SIEM Fundamentals

Ingestion and parsing . Normalisation . Search queries . Dashboards
Tools — Splunk, Wazuh, ELK Stack
Module 04

Alert Triage

Alert anatomy . Enrichment . True vs false positive . Priority matrix
Lab
Triage Queue Exercise
Module 05

Threat Frameworks

MITRE ATT&CK . Tactics and techniques . Gap analysis . Kill chain . Detection coverage mapping
Module 06

Detection Engineering

Rule writing . Thresholds and baselines . Testing detections . Sigma rules . Tuning
Lab
Custom Detection Rule
Module 07

Threat Intelligence

IOCs and IOAs . Reputation lookups . Malware triage basics . Feeds . Phishing analysis
Tools — ISP
Module 08

Incident Response

Playbooks . Forensic capture . Reporting . Lessons learned
Project — Containment Decisions, Communication

Assessment & certification

Module assignments and labs
25%
Mini projects
20%
Internal assessments
15%
Final project and review
40%

Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.

Career outcomes . Roles this programme prepares for
SOC Analyst (tier 1/2)Security Operations EngineerIncident Response AnalystThreat Detection EngineerCyber Security Analyst
Enquire or apply →Programme sheet (PDF)Institutions can commission a cohort

Also in Security