
What is Data
CIA Triad (Confidentiality, Integrity, Availability)
Defense in Depth
What is a Computer
How Data is Processed
Data at Rest / In Transit / In Use
OSI Model
TCP/IP Model
Real-world examples:
Two computers in LAN
Email flow (Gmail example)
Messaging flow (WhatsApp example)
1️⃣ Networking Basics
What is a Network
LAN / WAN / MAN
IP Addressing (Public vs Private)
DNS
Ports & Protocols (HTTP, HTTPS, FTP, SSH, SMTP)
2️⃣ Network Devices
Switch
Router
Firewall
Proxy
IDS / IPS
WAF
DMZ
Web Gateway
Email Gateway
NDR
3️⃣ Network Architecture (ADD HERE)
Explain:
Flat network vs Segmented network
3-tier architecture
Enterprise network layout
Internet → Firewall → DMZ → Internal network → Server zone
What is a Threat?
What is a Vulnerability?
What is Risk?
Types of Attacks:
Phishing
Malware
Ransomware
MITM
DDoS
SQL Injection
XSS
How attackers think
Social Engineering
? Lockheed Martin Cyber Kill Chain
Explain the 7 stages:
Reconnaissance
Weaponization
Delivery
Exploitation
Installation
C2
Actions on objectives
? MITRE ATT&CK Framework
Explain:
Tactics
Techniques
Real-world mapping
Why SOC teams use it
Security Concepts
Encryption (Symmetric / Asymmetric)
Hashing
Encoding
Digital Signatures
SSL/TLS
PKI
Authentication vs Authorization
MFA
VPN
2️⃣ Security Architecture
Explain:
Layered security model
Zero Trust concept
Segmentation
Endpoint Security
Email Security
Cloud Security
Defense in Depth (revisit deeper)
1. What is SIEM
2. Log Types:
o Windows Logs
o Network Logs
o Firewall Logs
o Authentication Logs
o IDS/IPS Logs
o Router Logs
o WAF Logs
o DLP Logs
o Load Balancer Logs
o Raw Logs vs Structured Logs
o NDR Logs
o XDR/EDR/AV Logs
o Email Gateway Logs
o Web Gateway Logs
o
3. Windows Event IDs
4. Use Case Creation
5. Alert vs Incident
6. SOC Levels (L1, L2, L3)
7. Playbooks
Phishing Investigation
Brute Force Attack
Ransomware Infection
Suspicious PowerShell Execution
Data Exfiltration Case
Insider Threat
Lateral Movement Detection
Web Attack Case
Cloud Misconfiguration
Privilege Escalation
Each case should include:
Alert received
Logs analyzed
Hypothesis
Investigation steps
Root cause
Containment
MITRE mapping
Kill chain stage
Final report
This makes you industry-ready.
Practicals on LetsDefend Platform
Revising the topics from foundations to NIST Incident Response.
Career & Industry Readiness and discuss about Q n A
Happy Learning. Happy Hunting
Cybersecurity is one of the fastest-growing and most in-demand fields in the technology industry. Organizations across the globe are actively seeking skilled professionals who can monitor, detect, investigate, and respond to security threats.
This comprehensive course is designed to help beginners and aspiring security professionals build a strong foundation in cybersecurity and develop the practical skills required to start a career as a Cybersecurity Analyst.
What you will learn:
Security Operations Center (SOC) Processes and Workflows
• Security Information and Event Management (SIEM)
• Endpoint Detection and Response (EDR)
• Extended Detection and Response (XDR)
• Threat Intelligence and Threat Hunting
• Log Analysis and Security Monitoring
• Incident Detection and Investigation
• Security Tools Used in Enterprise Environments
• Real-World Cybersecurity Attack Scenarios
• Resume Building and Interview Preparation
By the end of this course, you will understand how security analysts detect threats, investigate incidents, analyze logs, respond to attacks, and protect enterprise environments. You will also gain the knowledge and confidence needed to pursue entry-level cybersecurity roles such as SOC Analyst, Security Analyst, Incident Response Analyst, and Cybersecurity Operations Associate.
Whether you are a student, IT professional, system administrator, network engineer, or someone looking to transition into cybersecurity, this course will provide a structured roadmap to launch your career as a Cybersecurity Analyst.