
In this video you will be briefly get to know about the concepts you are going to learn.
Understand data at rest, data in transit, and data processing, and how host based firewall, antivirus, and encryption protect home and enterprise networks.
Explore how organizations segment networks with perimeter and internal firewalls, load balancers, and a DMZ to protect public web traffic and keep critical data in private networks.
Explore application and presentation layer basics in the ISO model, focusing on client requests and server responses. Understand how encoding, compression, and secure connections shape web content presentation.
Learn how cookies enable session continuity across web pages. Discover the ISO model’s session, transport, network, and data link layers, and how TCP/UDP, IP, DNS, and ports enable end-to-end communication.
Learn the iso model recap, distinguishing application, presentation, and session roles, and explain public versus private ip ranges, dns, dhcp, tcp vs udp, and basic network architecture.
Learn how web servers process get, post, head, put, and delete requests, interpret 200, 404, 403, 400, and 5xx status codes, and monitor redirects for SOC security.
Understand http and https traffic, analyze request headers, user agents, and cookies, and map port usage (80/443, ftp, ssh, dns) to detect abuses and threats.
Explore SMB and NetBIOS fundamentals, Samba file sharing, and the ransomware risk, then learn horizontal and vertical port scanning with Nmap to identify SMB ports such as 445 and 135–139.
Explore the evolution and architecture of Windows, learn about file systems, partitioning, drivers and kernel interactions, and master file and folder permissions for users and groups.
Explore how http and https requests and responses operate, including get and post methods, headers and body, and how dns resolves domains through root servers, top-level domains, and authoritative servers.
Learn the CIA security triad—confidentiality, integrity, availability—through encryption and hashing, covering data in transit, at rest, and during processing in a SIEM context.
Explore defense in depth for cyber security, detailing threats from black hat, hacktivist, and state actors, and applying layered controls like perimeter and internal firewalls, ids/ips, hardening, and compliance standards.
Explain the cyber kill chain and phases of attack, from reconnaissance (active and passive) to weaponization, delivery, exploitation, installation, and command-and-control, with real-world examples like eternal blue and ransomware payloads.
Analyze how brute force attacks harvest usernames and passwords, exploit authentication servers in private networks, and how multi-factor authentication, hashing, and captchas defend against credential stuffing and dictionary attacks.
Learn how phishing and spoofing attacks exploit credentials and trust, covering brute force password guessing, salt and hash defenses, and DNS, email, IP, and MAC spoofing detection.
Explore the OWASP top 10 web vulnerabilities, including injection and cross-site scripting, and learn practical detection, logging, and vulnerability management using Nessus and Tenable.
Understand DNS spoofing and how attackers use DNS tunneling to move data over port 53, and learn detection tactics with firewall rules, DNS inspection, and outbound DNS alerts.
Master Splunk installation and data ingestion from data sources, including Windows and Linux logs. Explore Splunk Enterprise Security and Splunk Security Essentials for alerting, correlations, and dashboards in SOC.
Explore how to upload and organize logs in Splunk, create indexes and dashboards, and build reports and alerts to monitor firewall, web, and other security data.
Explore how a soc aggregates logs from diverse sources, stores them in hot, warm, and cold tiers, and uses parsers, correlation rules, alerts, and dashboards in siem tools.
Explore Palo Alto firewall logs—traffic, system, and threat—and how nat translates private IPs to public IPs, with source and destination IPs and ports in inside-to-outside traffic for siem.
Build a Splunk firewall dashboard from Palo Alto logs, tracking blocked and allowed connections, configuring Palo Alto add-on, data models, source types, and indices for real-time security monitoring.
Create Splunk firewall dashboards by indexing pan traffic, extracting action, source, destination, ports, protocol, and time, then visualize blocked vs allowed traffic with timechart and stats.
Analyze network traffic with Suricata logs in Splunk to detect signatures, generate alerts by severity, and trace events using source IP, destination IP, and ports.
Learn to profile dns traffic with dns logs fields, identify good vs bad domains, use splunk intelligence to detect baby domains, fast flux, and domain generation patterns.
Learn to interpret dns logs in splunk, decoding fields like query, hostname, source and destination ip, and bytes. Spot patterns like nxdomain and dns tunneling.
Learn http basics, including http vs https on ports 80 and 443, common request methods like get, post, put, and delete, and 2xx to 5xx response codes.
Explore HTTP dashboards in Splunk to monitor http activity and overview, analyze requests per second, bytes in/out, and status codes for early anomaly detection.
Explore antivirus logs within a Splunk SIEM framework, learning to categorize with source, source type, and index, and to use signature and action fields to detect threats.
Windows log sources, Event Viewer, and Splunk forwarders for collecting and parsing security events, using IDs such as 4624, 4625, 4720, and 4740.
Learn how Windows Sysmon logs augment Windows event logs by detailing process creation, network connections, and file creation times, enabling threat hunting and investigation in Splunk.
In the siem use cases part 2, learn to detect web attacks in Splunk's platform, including command injection, sql injection, and cross-site scripting, by monitoring user agents, hosts, and urls.
Master SIEM use cases by analyzing log clearing thresholds, source IPs, and PowerShell activity with Windows and Sysmon logs, while building dashboards with blacklist and user-agent filters.
Explore the six stages of incident handling—preparation, identification, containment, remediation, recovery, and aftermath—in a cyber security soc analyst context with Splunk guidance.
Learn to hunt brute force attacks by analyzing post requests and form data in a SIEM (Splunk), identify suspicious source IPs, and correlate indicators of attack versus compromise.
Learn to analyze email headers and mail flows using smtp and mta, identify sender legitimacy with spf, dkim, and dmarc, and use splunk for threat lookup.
In this section you will learn interview questions of networking related concepts
Explore public and private IP addresses, classify IP address types, and review class a, b, and c ranges alongside private addressing and address translations.
Discover how firewalls act as the first line of defense, filtering inbound and outbound traffic through rules that permit or block access based on source, destination, and ports.
Describe cryptography basics, differentiating symmetric encryption, which uses the same key for encryption and decryption, from asymmetric encryption, which relies on public and private keys for secure data exchange.
Explain the CIA triad—confidentiality, integrity, and availability—and show how encryption preserves confidentiality, hashing protects integrity, and replication with load balancing sustains availability.
Discover how ssl provides a security layer on top of the http protocol, clarifying the relationship between ssl and https and when secure connections are used.
Stay up to date on cyber security news and latest attacks by monitoring CERT advisories, CVE updates, indicators of compromise, and vendor security alerts for timely responses.
Explain how a virus infects files and a worm replicates across networks by scanning for shared folders, spreading to other machines, and creating malware swarms.
Discover how brute force attacks occur, how failed logins across multiple accounts from the same IP trigger alerts, and how Splunk SIEM detects and correlates them to stop credential stuffing.
Discover how a SIEM like Splunk collects logs from diverse sources, parses and normalizes data into structured events, and correlates them to detect sophisticated attacks with alerts.
Analyze operating system and database event logs with Splunk, covering user and group changes, logon/logoff, account locks, process and service events, file and registry permissions, backups, and audit logs.
Examine how organizations deploy perimeter firewalls, DMZ, load balancers, and web application firewalls to protect public and private networks, while SOC analysts analyze logs and alerts.
Explore the roles and responsibilities of a soc engineer in a 24/7 security operations center. Understand continuous monitoring, dashboards, alerts, incident management, and knowledge transfer across L1–L3 with cross-team collaboration.
Explore how to create and track security incidents in ServiceNow, including fields like incident number, assignment group, affected resources, location, category, priority, and the incident lifecycle from new to close.
Define service level agreements for SOC incidents, outlining response times and required initial analysis for B1, B2, and B3 alerts, paging, escalation, and collaboration with internal teams or MSPs.
Determine log sources and data volumes for a 1500-server environment, including Linux, Windows, firewalls, web apps, and databases, generating 250–300 GB daily and 60–70 alerts.
Explore the incident response lifecycle for security incidents, detailing preparation, identification, containment, remediation, recovery, and lessons learned to prepare with contacts and procedures.
Learn how to manage security operations across shifts by maintaining shift documents, handing over incident analyses, monitoring dashboards, and generating timely reports for the next team.
Cyber Security SOC analyst training Splunk (SIEM) For those who are aspiring to certify themselves as well as enhance their knowledge and skills on becoming a SOC analyst. This course is specially designed for all level of interested candidates who wants get in to SOC.
Work of a SOC analyst?
A Security Operation Center Analyst is primarily responsible for all activities that occur within the SOC. Analysts in Security Operations work with Security Engineers and SOC Managers to give situational awareness via detection, containment, and remediation of IT threats. With the increment in cyber threats and hacks, businesses are becoming more vulnerable to threats. This has significantly enhanced the importance of a SOC Analyst. For those in cybersecurity, it can be a dynamic role. SOC Analysts cooperate with other team members to detect and respond to information security incidents, develop and follow security events such as alerts, and engage in security investigations.
Furthermore, SOC Analysts analyze and react to undisclosed hardware and software vulnerabilities. They also examine reports on security issues and act as ‘security advisors’ for an organization.
This course helps you to learn and implement those strategies and with training provided. This will in turn help you play a significant role in defending against cyber threats and keeping sensitive information secure.