Choose your language
Security Analyst Course
More than 2 million learners worldwide

Security Analyst Course

Launch or advance your cybersecurity career with a comprehensive Security Analyst course built around the skills employers actually test for. From log analysis and network traffic inspection to threat hunting and incident response, every module is grounded in real SOC workflows. This course prepares you to work confidently across the tools, frameworks, and processes that define modern security operations.

Dedika for businesses

What you will learn:

You will build a complete security analyst skill set covering threat detection, vulnerability management, endpoint forensics, and cloud security monitoring. You will learn to configure and query SIEM platforms, write detection rules, and manage the full incident response lifecycle. The course covers MITRE ATT&CK-based threat intelligence, malware analysis fundamentals, and security automation using SOAR platforms and Python scripting. You will also develop the communication skills needed to brief executives and coordinate cross-team response. By the end, you will be prepared to perform at a professional level inside a security operations centre.

How you study in practice Security Analyst Course

How you practise Security Analyst Course

For companies looking to train their teams

With Dedika for Businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Security Analysis

  • Lesson 1 • The Security Analyst Role

    Defines analyst responsibilities, career tiers, and daily workflows. Establishes professional context before technical content is introduced.

  • Lesson 2 • Networking Fundamentals for Analysts

    Reviews TCP/IP, DNS, HTTP, and common protocols analysts encounter daily. Enables accurate traffic interpretation in later monitoring chapters.

  • Lesson 3 • Core Cybersecurity Concepts

    Covers the CIA triad, authentication models, and basic cryptography. Provides the vocabulary needed for all subsequent technical chapters.

  • Lesson 4 • Operating System Security Basics

    Introduces Windows and Linux security features, user permissions, and logging. Prepares analysts to investigate host-based evidence.

  • Lesson 5 • Understanding the Threat Landscape

    Surveys attacker motivations, threat actor categories, and current attack trends. Grounds analysts in real-world adversary context.

Chapter 2See details

Security Monitoring and Log Analysis

  • Lesson 1 • Writing Effective Detection Rules

    Teaches rule logic, threshold tuning, and correlation queries. Directly enables alert creation covered in the next section.

  • Lesson 2 • Alert Triage and Prioritization

    Covers alert severity scoring, triage workflows, and escalation criteria. Builds the decision-making foundation for incident response.

  • Lesson 3 • Log Sources and Collection Methods

    Identifies critical log sources including firewalls, endpoints, and applications. Establishes what data feeds into a monitoring pipeline.

  • Lesson 4 • SIEM Platforms and Configuration

    Explains SIEM architecture, data ingestion, and normalization. Analysts learn to configure parsers and manage log pipelines.

  • Lesson 5 • Dashboards and Reporting

    Guides analysts in building operational dashboards and producing management reports. Connects monitoring data to business communication.

Chapter 3See details

Network Traffic Analysis

  • Lesson 1 • Packet Capture Fundamentals

    Introduces capture tools, filter syntax, and capture file formats. Provides the technical baseline for all traffic analysis tasks.

  • Lesson 2 • Protocol Dissection and Inspection

    Examines HTTP, DNS, SMB, and TLS traffic at the packet level. Enables analysts to distinguish normal from suspicious protocol behaviour.

  • Lesson 3 • Intrusion Detection System Tuning

    Teaches IDS/IPS rule management, signature updates, and performance tuning. Ensures detection infrastructure remains accurate and efficient.

  • Lesson 4 • Detecting Network-Based Attacks

    Applies protocol knowledge to identify scans, lateral movement, and exfiltration. Bridges traffic analysis skills to real attack scenarios.

  • Lesson 5 • Network Flow Analysis

    Covers NetFlow, IPFIX, and flow-based anomaly detection at scale. Complements full-packet analysis with high-volume traffic visibility.

Chapter 4See details

Endpoint Detection and Response

  • Lesson 1 • Endpoint Containment and Remediation

    Teaches host isolation, artifact removal, and recovery validation. Connects detection findings to actionable response steps.

  • Lesson 2 • Process and Memory Analysis

    Covers process tree inspection, memory artifact identification, and injection detection. Builds skills for detecting fileless and in-memory threats.

  • Lesson 3 • Persistence Mechanism Detection

    Identifies registry-based, scheduled task, and service persistence techniques. Ensures analysts can find attacker footholds on compromised hosts.

  • Lesson 4 • Endpoint Telemetry and EDR Platforms

    Surveys EDR agent architecture, telemetry types, and deployment models. Establishes the data foundation for host-based investigations.

  • Lesson 5 • Windows Event Log Investigation

    Focuses on critical Windows event IDs, audit policy configuration, and log correlation. Enables rapid identification of malicious host activity.

Chapter 5See details

Threat Intelligence and Indicator Management

  • Lesson 1 • Adversary Profiling with MITRE ATT&CK

    Applies the ATT&CK framework to map adversary TTPs and coverage gaps. Directly informs detection rule development and hunt priorities.

  • Lesson 2 • Indicator of Compromise Management

    Covers IOC types, ingestion pipelines, and indicator lifecycle management. Enables automated enrichment of alerts with threat context.

  • Lesson 3 • Threat Intelligence Platforms

    Examines TIP architecture, feed integration, and analyst workflows. Connects raw intelligence data to operational detection use cases.

  • Lesson 4 • Threat Intelligence Fundamentals

    Defines intelligence types, the intelligence cycle, and analyst use cases. Provides the conceptual framework for all intelligence-driven activities.

  • Lesson 5 • Producing Intelligence Reports

    Teaches structured report formats, confidence language, and stakeholder targeting. Ensures intelligence findings drive decisions at all organisational levels.

Chapter 6See details

Vulnerability Management and Assessment

  • Lesson 1 • Communicating Vulnerability Risk

    Guides analysts in translating technical findings into business risk language. Supports executive reporting and remediation prioritisation decisions.

  • Lesson 2 • Remediation Tracking and Verification

    Teaches patch management integration, exception handling, and rescan validation. Connects vulnerability findings to measurable risk reduction.

  • Lesson 3 • Vulnerability Scoring and Prioritization

    Applies CVSS, exploitability data, and asset criticality to rank findings. Ensures remediation effort targets the highest-risk vulnerabilities first.

  • Lesson 4 • Vulnerability Management Lifecycle

    Defines discovery, assessment, prioritisation, remediation, and verification phases. Frames all scanning and tracking activities within a repeatable process.

  • Lesson 5 • Scanning Tools and Techniques

    Covers authenticated vs. unauthenticated scans, scan profiles, and output formats. Enables analysts to configure and execute effective vulnerability scans.

Chapter 7See details

Incident Response and Case Management

  • Lesson 1 • Incident Response Lifecycle

    Maps the preparation, detection, containment, eradication, and recovery phases. Provides the procedural backbone for all response activities.

  • Lesson 2 • Post-Incident Review and Improvement

    Guides analysts through after-action reviews, root cause analysis, and control improvements. Closes the response loop with measurable security gains.

  • Lesson 3 • Coordinating Cross-Team Response

    Addresses communication protocols, stakeholder roles, and external coordination. Prepares analysts to operate within larger incident response teams.

  • Lesson 4 • Case Management and Documentation

    Covers ticketing systems, evidence chain of custody, and timeline construction. Ensures investigations are reproducible and legally defensible.

  • Lesson 5 • Containment and Eradication Techniques

    Details network segmentation, account disabling, and malware removal procedures. Builds on endpoint and network skills from prior chapters.

Chapter 8See details

Advanced Threat Hunting and Detection Engineering

  • Lesson 1 • Measuring and Improving Detection Coverage

    Uses ATT&CK coverage mapping, purple team exercises, and metrics to assess gaps. Drives continuous improvement of the detection programme.

  • Lesson 2 • Threat Hunting Methodology

    Introduces hypothesis-driven hunting, data source selection, and hunt planning. Establishes the structured approach that separates hunting from reactive monitoring.

  • Lesson 3 • Behavioural Detection and Analytics

    Applies UEBA, machine learning signals, and behavioural baselines to detection. Extends rule-based detection with anomaly-driven approaches.

  • Lesson 4 • Detection Engineering Principles

    Defines detection-as-code, rule quality standards, and testing frameworks. Elevates detection from ad hoc rules to engineered, maintainable content.

  • Lesson 5 • Hunt Execution and Analysis

    Covers query construction, statistical baselining, and anomaly investigation. Applies skills from monitoring and network chapters to proactive discovery.

Certification

Your valid completion certificate

This course is for you:

  • IT support technician: ready to pivot into a dedicated security role.

  • Recent computer science graduate: seeking practical, employer-relevant defensive security skills.

  • Network administrator: wanting to add threat detection expertise to existing responsibilities.

  • Career changer from a non-tech field: motivated to enter cybersecurity from the ground up.

  • Junior SOC analyst: looking to fill knowledge gaps and advance to the next tier.

  • Hobbyist security enthusiast: ready to turn personal interest into a professional skill set.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQs

Who is Dedika?

Is the certificate valid in Pakistan?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course