Course Image

discounted

Security operation center V1

$0.00

Course Category

Security operation center

Hours

30

Videos

116

Files

0

Level

Beginners

Ratings

4/5

Details

The course starts by introducing the concept of the SOC, its structure, processes, and operational tiers. It then covers essential networking fundamentals required for SOC analysts, including protocols, services, and how network traffic is leveraged in cyber attacks. Participants will gain a comprehensive overview of common and advanced cyber attacks such as IP spoofing, DDoS, DNS poisoning, brute force, privilege escalation, phishing, SQL injection, zero-day attacks, and more — with a focus on how these attacks appear in logs and network traffic. A major part of the course focuses on SIEM technologies, explaining how SIEM systems work, their capabilities, and how they differ from log management systems. The course provides in-depth training on Splunk, including architecture, data ingestion, SPL searching, reports, dashboards, alerts, lookups, event types, and performance optimization. Advanced topics include OSINT fundamentals, Threat Intelligence, Incident Response, and the MITRE ATT&CK® framework, with an overview of real-world APT group behaviors.

What you'll learn

  • The course concludes with intensive hands-on labs, covering:
  • SIEM-based investigation of APT attacks
  • Ransomware incident analysis
  • Log analysis using Splunk
  • Malware traffic analysis using Wireshark
  • Learning Outcomes
  • By the end of this course, participants will be able to:
  • Perform the role of a junior to mid-level SOC Analyst
  • Analyze and investigate security incidents using logs
  • Effectively use Splunk for threat detection and incident response
  • Map attacks to the MITRE ATT&CK framework
  • Apply structured incident response methodologies in real-world scenarios

01 Introduction to SOC.mp4

02 SOC Building

03 SOC Process

04 SOC Tiers

05 SOC VS SIEM

06 Conclusion

01 IntrotoNetwork

02 OSI Layers

03 Network Devices Types

04 TCP IP _ IP classifcation

05 TCP _ UDP

06 ICMP

08 HTTP _ HTTPS

13 conclusion

12 SMTP

11 FTP _ TELNET _ SSH

10 DHCP

09 DNS

0Overview

01 IP Spoofing

02 TCP IP Hijacking

03 TCP SYN Floods

04 DOS DDOS Attack

05 Fragmentation Overlapping Attack

06 DNS Spoofing

07 ARP Poisoning

08 Port Scanning Attack

09 Brute Force Attack

10 Privilege Escalation

11 Phishing Attack

12 Phishing APTs

13 Malware Attack

14 SQL Injection

15 Sensitive Data Exposure

16 Broken Authentication

17 XML External Entities Attack

18 Broken Access Control Attack

19 Insecure Deserialzation Attack

20 Using Components with know Vulnerabilities

21 Insufficient Logging and Monitoring

22 Zero Day Attack

23 Conclusion

00 Overview

01 What is SIEM

02 SEM VS SIM

03 SIEM VS LM

04 SIEM Capabilities

05 Definitions in SIEM

06 SIEM Process

07 How SIEM works

08 SIEM Tools

09 SIEM Cloud Services(Live)

10 Why should we use SIEM

11 Intrusion Detection Systems

12 Intrusion Prevention Systems

13 IDS VS IPS

14 Firewalls

15 Antivirus.

16 Log Management

17 Conclusion

01 Introduction to Splunk

02 What is Splunk

03 Splunk Architecture

04 How Splunk works

05 important Definitions in Splunk

06 Install Splunk _ Splunk Cloud

07 Spunk Interfaces

08 Data Ingestion in Splunk

09 Source types in Splunk

10 Spunk Search 1

11 AND , OR Operators

12 Splunk Field Searching

13 Splunk Time Range Search

14 SPL Overview and Examples

15 SPL Components and Examples

16 Splunk Reports

17 Splunk Dashboard

18 Dataset in Splunk

19 Splunk Lookups

20 Schedules and Alerts in Splunk

21 Splunk search macros

22 Splunk Event Types

23 Splunk Chart

24 Splunk Overlay Char

25 Splunk Sparkline

26 Splunk Managing Indexes

27 Splunk Tags

28 Splunk Apps

29 Splunk Removing Data

30 Splunk Transforming Commands

31 Splunk Sort Command

32 Splunk Top command

33 Splunk Status command

34 Splunk Documentation

35 List of search commands

36 Splunk cheat sheet

01 OSINT Fundamental

02 Threat Intelligence Fundamental

03 Incident response Fundamental

04 SOC Analyst Tools

05 MITRE ATT_CK®

SOC Analyst Interview Questions _ Answers

01 SIEM Case Investigation (APTAttack)

02 SIEM Case Investigation (Ransomware Attack )

03 Hammered Log Analysis

04 Malware Traffic Analysis