SOC analyst: intrusion detection and SIEM investigation
Your security alerts need to lead to relevant analysis and action. Structure detection, assessment and investigation to distinguish useful signals from noise. Strengthen your ability to document incidents and coordinate their handling within your defence capabilities.
- Duration
- 5 days 35 hours
- Code
- CYBER002FR Code
Presentation
As cyberattacks increase in frequency and complexity, establishing a Security Operations Center (SOC) has become essential for organisations. This SOC analyst course provides the foundational skills to join a cyber defence team and play a key role in protecting information systems. You will learn to detect, analyse and respond effectively to security incidents threatening a business.
This SOC training programme guides you through implementing essential security technologies.
You will learn to deploy detection solutions on endpoints (EDR) and networks (NIDS), then centralise and analyse events using a security information and event management system (SIEM).
The course covers the entire process, from log collection to creating relevant correlation rules to identify suspicious activity.
By the end of this 5-day course, you will have developed a cybersecurity analyst's mindset. You will be able to conduct a digital investigation from start to finish: analyse attack traces in depth to extract indicators of compromise (IoCs) and use the SIEM to assess threats and orchestrate incident response.
Objectives
By the end of this SOC analyst course, you will be able to:
- Master the role, functions and structure of a Security Operations Center (SOC) to understand its overall operation ;
- Deploy and configure intrusion detection solutions such as NIDS (network detection) and EDR (endpoint detection) to protect infrastructure ;
- Implement and administer a security information and event management (SIEM) system, from log collection to detection rule implementation ;
- Analyse cyberattack traces to extract indicators of compromise (IoCs) and understand the attacker's methods ;
- Conduct a digital investigation using SOC tools, particularly the SIEM, to assess and respond to security incidents.
Program
Module 1: Mastering SOC fundamentals
- The definition, objectives and functions of a Security Operations Center (SOC).
- Different SOC team structures and how they operate.
- Key steps in establishing an operational security centre.
Module 2: Protecting endpoints with HIDS/EDR solutions
- Introduction to host-based intrusion detection systems (HIDS) and Endpoint Detection and Response (EDR) solutions.
- Applying endpoint-specific detection rules.
Practical exercises:
- Implement rules and detect endpoint attacks.
Module 3: Monitoring networks with NIDS/NDR solutions
- Introduction to network intrusion detection systems (NIDS) and Network Detection and Response (NDR) solutions.
- Strategic placement of a NIDS within the architecture and enabling traffic monitoring.
Practical exercises:
- Analyse malicious network captures (PCAP) to identify attacks and extract indicators of compromise (IoCs).
Module 4: Managing detection and investigation with a SIEM
- The definition, objectives and different architectures of Security Information and Event Management (SIEM).
- Implementing SIEM correlation rules for event analysis.
- Fundamental SIEM investigation methodologies.
Practical exercises:
- Deploy a SIEM and configure event collection.
- Create and apply SIEM detection rules.
- Conduct a complete investigation of a real incident case using the SIEM.
Audience
This course is intended for:
- System and network technicians and administrators who want to specialise in security incident detection and response;
- Security integrators who want to master the implementation and operation of SOC tools (SIEM, EDR, NIDS);
- Information security managers and engineers who want to understand how a SOC operates to guide cyber defence strategy more effectively;
- Technical project managers responsible for deploying a SOC or security tools;
- Anyone seeking to move into a cybersecurity analyst role.
Prerequisites
This course requires the following prerequisites:
- IT infrastructure and security fundamentals: a good understanding of computer systems and networks (TCP/IP principles and operating systems), along with familiarity with basic cybersecurity concepts.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Cybersecurity expert trainer: the course is delivered by a certified professional with hands-on SOC experience, ensuring learning grounded in the realities of the role.
- Application-focused learning: the programme devotes substantial time to practical exercises using key technologies (EDR, NIDS, SIEM), immersing you in attack scenarios and investigations based on concrete cases.
- Developing an analyst's mindset: beyond tools, the course teaches you to think like an analyst by analysing attacks, extracting indicators of compromise (IoCs) and conducting investigations from start to finish.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en