SOC Analyst (Blue Team)
Train for Security Operations Centre roles: network and OS security, SIEM with Splunk, Microsoft Sentinel and Wazuh, log analysis, incident response, threat intelligence, MITRE ATT&CK and EDR — the most fresher-friendly path into cyber security.
Best for: Graduates (B.Tech, BCA, B.Sc IT), network admins and IT support staff.
Syllabus — module by module
- CIA triad & threat landscape
- TCP/IP & ports
- Windows & Linux internals
- Common attack types
- Splunk searches & dashboards
- Microsoft Sentinel
- Wazuh open-source SIEM
- Use-case & alert tuning
- Windows event logs
- Firewall & proxy logs
- Wireshark packet analysis
- Phishing email analysis
- IR lifecycle (NIST)
- Triage & escalation
- Containment & eradication
- Reporting
- MITRE ATT&CK mapping
- IOCs & threat feeds
- Threat hunting
- Malware basics
- Endpoint detection & response
- SOAR automation
- AI copilots for analysts
- Mock SOC shift
Projects you build
- Build a home SOC lab with Wazuh
- Investigate a simulated ransomware incident
- Write detection rules mapped to MITRE ATT&CK
You will be able to
- Monitor and triage alerts in a SIEM
- Investigate incidents end-to-end
- Write clear incident reports
Tools & tech
Maps to CompTIA Security+ / CySA+ and Microsoft SC-200