Choose your language
SOC Analyst Course
More than 2 million students worldwide

SOC Analyst Course

4.4

Launch your career in cybersecurity with a comprehensive SOC Analyst course built for real-world operations. From SIEM platforms and threat intelligence to incident response and detection engineering, every module prepares you for the demands of a Tier 1 analyst role and beyond. This is hands-on, job-ready training that takes you from foundational concepts to advanced SOC skills.

Dedika for businesses

What you will learn:

You will learn how SOC teams are structured, how analysts triage alerts, and how to operate SIEM platforms to detect and investigate threats. The course covers networking fundamentals, Windows and Linux internals, endpoint detection tools, and log management. You will apply threat intelligence to enrich alerts, execute incident response procedures, and document findings professionally. Advanced topics include detection engineering, threat hunting, cloud security monitoring, and SOC metrics. By the end, you will have the technical knowledge and practical workflows to perform confidently as a SOC analyst.

How you study in practice SOC Analyst Course

How you practise SOC Analyst Course

For companies looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Security Operations

  • Lesson 1 • Core Analyst Responsibilities

    Outlines daily duties, documentation standards, and performance expectations for Tier 1 analysts. Sets professional baseline for the course.

  • Lesson 2 • Security Frameworks and Standards

    Introduces widely adopted security frameworks used to guide SOC operations and measurement. Connects framework concepts to analyst workflows.

  • Lesson 3 • SOC Purpose and Business Alignment

    Defines the SOC mission and its relationship to organisational risk. Anchors all subsequent technical work in business context.

  • Lesson 4 • SOC Models and Tier Structures

    Compares in-house, hybrid, and managed SOC models and analyst tier responsibilities. Provides structural context for the analyst role.

  • Lesson 5 • Legal and Ethical Analyst Obligations

    Covers data handling ethics, privacy obligations, and lawful monitoring boundaries. Ensures analysts operate within professional and legal limits.

Chapter 2See details

Networking and Protocol Fundamentals

  • Lesson 1 • Network Security Controls

    Reviews firewalls, IDS/IPS, proxies, and NAC as sources of security telemetry. Connects control logs to analyst detection workflows.

  • Lesson 2 • Core Protocols and Their Behaviour

    Examines TCP/IP, DNS, HTTP/S, SMTP, and other protocols analysts encounter daily. Links normal protocol behaviour to anomaly detection.

  • Lesson 3 • Network Architecture Essentials

    Covers LAN, WAN, DMZ, and segmentation concepts critical for understanding traffic flow. Provides the topology context for alert analysis.

  • Lesson 4 • Packet Capture and Traffic Analysis

    Teaches capture techniques and interpretation of packet-level data using analysis tools. Directly supports network-based alert investigation.

  • Lesson 5 • Wireless and Cloud Network Threats

    Extends networking knowledge to wireless and cloud environments analysts increasingly monitor. Prepares analysts for modern hybrid network visibility.

Chapter 3See details

Operating Systems and Endpoint Security

  • Lesson 1 • Endpoint Detection and Response Tools

    Introduces EDR platforms, their telemetry types, and alert triage workflows. Connects endpoint visibility to SOC detection pipelines.

  • Lesson 2 • Linux Internals for Analysts

    Examines Linux file system, processes, cron jobs, and syslog as detection sources. Extends endpoint knowledge to server and cloud workloads.

  • Lesson 3 • Windows Internals for Analysts

    Covers processes, registry, services, and event logs as detection data sources. Establishes Windows artefact knowledge used throughout the course.

  • Lesson 4 • Malware Behaviour on Endpoints

    Describes how common malware families interact with OS components to persist and evade. Prepares analysts to recognise malicious endpoint patterns.

  • Lesson 5 • Endpoint Artefact Collection

    Teaches collection of memory, disk, and log artefacts for investigation. Supports the incident response and forensics chapters that follow.

Chapter 4See details

Log Management and SIEM Operations

  • Lesson 1 • Log Sources and Collection Architecture

    Maps log sources across endpoints, network, and cloud to SIEM ingestion pipelines. Establishes data foundation for all SIEM-based detection work.

  • Lesson 2 • SIEM Platform Navigation

    Covers SIEM dashboards, search interfaces, and data models analysts use daily. Builds hands-on platform fluency required for alert investigation.

  • Lesson 3 • Correlation Rules and Use Cases

    Explains how correlation logic converts raw events into actionable alerts. Analysts learn to evaluate, tune, and create detection use cases.

  • Lesson 4 • Alert Triage in the SIEM

    Applies SIEM search skills to structured alert triage and investigation workflows. Directly prepares analysts for Tier 1 queue management.

  • Lesson 5 • SIEM Health and Data Quality

    Addresses log gaps, parsing errors, and SIEM performance monitoring. Ensures analysts can identify and escalate data quality issues.

Chapter 5See details

Threat Intelligence and Indicator Analysis

  • Lesson 1 • Indicators of Compromise and Enrichment

    Covers IOC types, quality assessment, and enrichment using threat platforms. Enables analysts to add context to raw alerts efficiently.

  • Lesson 2 • Threat Actor Profiling

    Introduces adversary taxonomy, motivation models, and campaign tracking methods. Helps analysts contextualise alerts within broader threat actor behaviour.

  • Lesson 3 • MITRE ATT&CK Applied to Detection

    Maps ATT&CK tactics and techniques to SIEM rules and alert enrichment. Connects framework knowledge to practical detection engineering.

  • Lesson 4 • Threat Intelligence Fundamentals

    Defines intelligence types, the intelligence lifecycle, and producer-consumer relationships. Grounds all subsequent intelligence work in structured methodology.

  • Lesson 5 • Intelligence Sharing and Reporting

    Covers STIX/TAXII standards, sharing communities, and analyst reporting formats. Prepares analysts to contribute intelligence back to the community.

Chapter 6See details

Incident Detection and Triage

  • Lesson 1 • Incident Scoring and Escalation

    Covers risk-based scoring models and escalation criteria for Tier 2 handoff. Ensures consistent escalation decisions across the analyst team.

  • Lesson 2 • Triage Documentation and Ticketing

    Establishes standards for recording triage findings in ticketing systems. Produces investigation records that support downstream response and reporting.

  • Lesson 3 • Alert-to-Incident Classification

    Defines the distinction between events, alerts, and incidents using severity criteria. Establishes the classification logic analysts apply to every queue item.

  • Lesson 4 • Attack Pattern Recognition

    Trains analysts to recognise multi-stage attack patterns across kill chain phases. Connects individual alerts to broader attack narratives.

  • Lesson 5 • Structured Triage Methodology

    Applies a repeatable triage process using enrichment, pivoting, and context gathering. Reduces mean time to triage through disciplined workflow.

Chapter 7See details

Incident Response and Containment

  • Lesson 1 • Containment Strategies and Execution

    Covers short-term and long-term containment options across endpoint, network, and identity. Analysts practice selecting and executing containment actions.

  • Lesson 2 • Evidence Preservation During Response

    Applies forensic principles to live response to ensure evidence integrity. Supports legal and post-incident review requirements.

  • Lesson 3 • Eradication and Recovery Operations

    Details steps to remove threat actor presence and restore systems safely. Prevents reinfection through validated recovery procedures.

  • Lesson 4 • Incident Response Lifecycle

    Maps the six-phase IR lifecycle and analyst responsibilities at each stage. Provides the procedural framework for all response activities.

  • Lesson 5 • Post-Incident Review and Lessons Learned

    Structures the post-incident review process to extract actionable improvements. Closes the feedback loop between response and detection engineering.

Chapter 8See details

Advanced Detection and SOC Maturity

  • Lesson 1 • SOC Maturity Models and Roadmaps

    Applies maturity models to assess current SOC capability and plan improvements. Prepares senior analysts to contribute to strategic SOC development.

  • Lesson 2 • Threat Hunting Methodology

    Covers hypothesis-driven hunting using ATT&CK and behavioural analytics. Transitions analysts from reactive to proactive threat discovery.

  • Lesson 3 • Detection Engineering Principles

    Introduces detection-as-code concepts, rule lifecycle management, and quality metrics. Enables analysts to contribute to the detection content pipeline.

  • Lesson 4 • SOC Metrics and Performance Management

    Defines key SOC metrics, measurement methods, and reporting to leadership. Enables data-driven SOC improvement and analyst accountability.

  • Lesson 5 • Security Orchestration and Automation

    Introduces SOAR platforms, playbook design, and automation use cases for SOC efficiency. Reduces analyst toil through structured automation.

Certification

Your valid completion certificate

This course is for you:

  • IT help desk technician: ready to move into a dedicated security role.

  • Recent computer science graduate: seeking a structured entry point into cybersecurity.

  • Network administrator: wanting to add threat detection skills to existing expertise.

  • Career changer from a non-technical field: motivated to enter the security industry.

  • Self-taught security enthusiast: looking to formalise knowledge into employable credentials.

  • Military veteran with IT background: transitioning into civilian cybersecurity employment.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in Nigeria?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course