
Explore the multi-level vision of security operations centers, cover services, organization, governance, and incident response, with live demos, a normalized service catalog, and metrics to drive change.
Explore the SOC career landscape through the trainer's overview. Learn how roles from a level 3 SOC analyst to data scientist drive incident detection, threat intelligence, audits, and tooling.
Define the security operations center, explain its components and roles, and outline the monitor, detect, and respond workflow to protect the organization.
Explore the birth of security operations centers from the 1970s to today, tracing five generations, and key milestones like antivirus, firewalls, proxies, and intrusion detection.
The second generation of security operations centers evolves during the malware era after 1995, driven by mass-mail viruses and backdoor exploits, with MSSP services and CCM as core.
Cybercrime fuels the 3rd generation socs, prioritizing intrusion prevention and early detection under laws like SB 1386 and the Budapest Convention, with certs and PCI standards shaping defenses.
Explore the fourth generation of security operations centers from 2006 to 2013, covering advanced persistent threats, data exfiltration detection, and the rise of hacktivism, nation-state attacks, and major breaches.
Explore the fifth generation of security operations centers, driven by adversary and threat intelligence and automation. See red and blue teams, hunting workgroups, and information sharing from CERTs and communities.
Explore the deep dive into a security operations center with a formal SOC service catalog. Learn about monitoring, analysis and response, and threat intelligence, plus roles and workflows.
Learn how the monitoring service uses SIEM and SOAR to manage centralized log management and log sources, analyze alerts, and drive ticketing, triage, and playbooks for incident response.
The analysis and response service handles tier 2 alerts, defines use cases, and conducts incident response, escalating to tier 3, aligning with P1–P3 priorities, and coordinating with SIEM and EDR.
Understand threat intelligence within the SOC by collecting data into a threat intelligence platform, classifying it as strategic, tactical, and telemetry data, and feeding IoCs to detection tools.
Develop and document use cases for monitoring, detection, and response in the security operations center, applying iterative procedures and frameworks to detect data exfiltration via usb, c2, web services, dns.
Apply incident response workflows in a security operations center, using IBM Resilient, IBM Crusader, FireEye EDR, and Symantec to address incidents: adware, indicator of compromise, post intrusion, and PowerShell DLL.
Investigate adware on an end-user workstation by validating detections, performing triage and forensics, and containing and rebuilding the machine. Block malicious domains and phishing sources to prevent further compromise.
Investigate a threat intelligence IOC by validating the IP indicator with reports, tracing its origin via web proxy logs and siem, then remediate by removing the malicious Excel file.
Examine post intrusion reconnaissance in a compromised system, including net user /domain, to map domain trusts and guide triage and validation of a true positive with no impact.
Learn how a PowerShell–created DLL triggers an EDR alert, and how analysts triage, sandbox, decompile a .NET DLL to confirm a false positive.
Drive change in a security operations center by consolidating lessons from prior sessions, understanding SOC structure, governance, roles, and KPIs, and identifying gaps to deliver value and maturity.
Explore the standard SOC structure and roles, from the director and incident manager to threat intelligence leads, SIEM architects, and tiered analysts, plus governance.
Explains a governance model for security operations centers, detailing roles, responsibilities of executive stakeholders, the SOC steering committee, the SOC core team, the log source community, the remediation and external inputs, and how KPIs guide initiatives.
Master the development and use of KPIs and KRIs to measure SOC effectiveness and risk, via extract-transform-load pipelines, dashboards, and actionable insights.
Explore a real-life SOC audit using three targeted questionnaires—organization, architecture, and incident response—to identify gaps, map tools, and drive change for secure operations.
Map the security operations center through an organization questionnaire, noting ceo, chief information security officer, and the executive leading digital strategy, alongside internal and external teams and change propositions.
Identify gaps in the SOC architecture by mapping core tools and log sources to Splunk, and propose changes like mail security, AD security, FIM, threat intel, PKI, and deception.
This lecture assesses incident response across preparation, identification, containment, eradication, recovery, and reporting, identifies gaps, and outlines concrete change propositions to strengthen SOC readiness.
Explore the evolution of security operation centers, their monitoring and analysis, incident response and threat intelligence, governance and metrics, including key performance indicators and key risk indicators.
Get valuable knowledge and good practices proven successful in the biggest SOCs !
The Security Operations Center market as a Service is expected to reach 83.55 billion US dollars by 2028 (source : Polaris Market Research).
As, myself, a SOC Consultant, I daily see that demands for SOC services and practitioners are growing constantly, without enough supply, especially for job positions.
This expanding market, along with the demand & supply gap, holds numerous opportunities for cyber security practioners, network engineers, computer scientists and even for analysts wannabees.
This is along with the very exciting context of SOCs.
SOC teams are striving in the biggest companies, and are responsible for major & challenging business use cases.
Security Operations Center is a relatively new model. And started to boom quite recently. Therefore, many of the SOC professionals have not a complete vision of their teams and models.
This course will give you valuable key elements to grasp that vision, and thus break confidently into a SOC.
This learning can be used as skills for managing a SOC Program. As well as comprehensive knowledge to dive into any other position in a SOC.
For members of the community : feel free to reach out if you want to discuss this course or any other topic related to cyber security & IT.