Perform a search on the site.

Your currency

SOC analyst: intrusion detection and SIEM investigation

Your security alerts need to lead to relevant analysis and action. Structure detection, assessment and investigation to distinguish useful signals from noise. Strengthen your ability to document incidents and coordinate their handling within your defence capabilities.

Duration
5 days 35 hours
Code
CYBER002FR Code

Presentation

As cyberattacks increase in frequency and complexity, establishing a Security Operations Center (SOC) has become essential for organisations. This SOC analyst course provides the foundational skills to join a cyber defence team and play a key role in protecting information systems. You will learn to detect, analyse and respond effectively to security incidents threatening a business.

This SOC training programme guides you through implementing essential security technologies. 
You will learn to deploy detection solutions on endpoints (EDR) and networks (NIDS), then centralise and analyse events using a security information and event management system (SIEM). 
The course covers the entire process, from log collection to creating relevant correlation rules to identify suspicious activity.

By the end of this 5-day course, you will have developed a cybersecurity analyst's mindset. You will be able to conduct a digital investigation from start to finish: analyse attack traces in depth to extract indicators of compromise (IoCs) and use the SIEM to assess threats and orchestrate incident response.

Objectives

By the end of this SOC analyst course, you will be able to:

  • Master the role, functions and structure of a Security Operations Center (SOC) to understand its overall operation ;
  • Deploy and configure intrusion detection solutions such as NIDS (network detection) and EDR (endpoint detection) to protect infrastructure ;
  • Implement and administer a security information and event management (SIEM) system, from log collection to detection rule implementation ;
  • Analyse cyberattack traces to extract indicators of compromise (IoCs) and understand the attacker's methods ;
  • Conduct a digital investigation using SOC tools, particularly the SIEM, to assess and respond to security incidents.
Last update: 24/09/2026