SOC & Blue TeamBeginner Level75 Hours Live

SOC Operations & Threat Hunting (Blue Team)

Real-time SIEM log analysis with Splunk, MITRE ATT&CK mapping, memory forensics, and PCAP incident triage.

Splunk Enterprise Log Analysis
Wireshark & Memory Forensics
CORTEX XDR Incident Playbooks
75 Hours Practical Workload
2 Core Modules
2 Sandboxed Labs
Cryptographic TS-ID Verifiable

Course Overview & Objectives

Train as an enterprise SOC Analyst. Learn how to ingest multi-source telemetries into Splunk, build automated correlation rules, investigate live ransomware outbreaks, and execute structured threat hunting using the MITRE ATT&CK framework.

What You Will Master

  • Operate Splunk Enterprise SIEM for real-time alerting and incident investigation
  • Map observed adversary behaviors to MITRE ATT&CK tactics and techniques
  • Analyze Wireshark PCAPs to detect command-and-control (C2) beaconing and data exfiltration
  • Perform volatility-based live memory forensics during simulated malware infections

Prerequisites

  • Basic operating system concepts (Windows/Linux)
  • Understanding of TCP/IP networking

Platforms & Tools Covered

SplunkWiresharkVolatility 3SysmonVelociraptorSuricata

Detailed Curriculum Modules

2 modules structured from foundational theory through complex adversarial execution.

75 Total Workload Hours
MODULE 01

SIEM Architecture & Splunk Fundamentals

2 Lessons

Ingesting Windows Event Logs, Sysmon, and Linux auth telemetries into a distributed SIEM.

Writing Performant SPL Queries & Search Macros
50m
Detecting Pass-the-Hash in Windows Security Logs
60m
MODULE 02

Network Traffic Analysis & PCAP Forensics

2 Lessons

Uncovering encrypted malware beacons, DNS tunneling, and cleartext credential harvesting in PCAPs.

Wireshark Advanced Display Filters for Beacon Detection
45m
Carving Executable Payloads from HTTP Streams
55m

Hands-on Virtual Sandbox Labs

Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.

LAB 01~60 mins

Splunk Ransomware Triage Challenge

Identify patient zero, infection vector, and lateral movement timeline in Splunk.

Skills Tested:Splunk, SPL, Incident Response
LAB 02~65 mins

Memory Forensics with Volatility 3

Extract injected DLLs and malicious process trees from infected memory dumps.

Skills Tested:Volatility, Memory Analysis

Faculty & Lead Instructor

Direct weekly instruction, live office hours, and code-review feedback.

VS

Vikramaditya Sharma

Thread Security Education

Principal SOC Engineer & Incident Commander

Former Lead Incident Responder managing 24/7 global defense operations, triage, and threat eradication.

Frequently Asked Questions

Everything you need to know about scheduling, cohort admissions, and lab access.

Will I learn how to use real enterprise SIEM tools?

Yes! You work directly inside a licensed enterprise Splunk environment with populated multi-gigabyte attack datasets.

What jobs does this qualify me for?

SOC Analyst Tier 1 & 2, Incident Responder, Threat Intelligence Analyst, and Junior Threat Hunter.

Ready to Master SOC Operations & Threat Hunting (Blue Team)?

Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.