Skip to main content

Course Curriculum

The curriculum is organised around employable SOC evidence rather than course completion.

Module 1 — SOC foundations

Outcomes

  • explain SOC roles, alert lifecycle, severity, escalation and evidence handling;
  • distinguish monitoring, detection, investigation and incident response;
  • use an investigation template consistently.

Assessment: capability matrix + one triage record.

Module 2 — Networking for analysts

Outcomes

  • reason about IP addresses, ports, protocols, DNS and TCP/UDP;
  • interpret source/destination context;
  • recognise common network evidence used in investigations.

Assessment: annotated network-flow analysis and packet/log notes.

Module 3 — Windows security telemetry

Outcomes

  • use Event Viewer and Windows Security logs;
  • interpret authentication activity and process evidence;
  • create timelines and correlate related events.

Assessment: Event 4625 investigation pack.

Module 4 — Wazuh SIEM operations

Outcomes

  • understand agent/manager/rule/alert relationships;
  • triage alerts systematically;
  • document rule tuning and false positives.

Assessment: three alert triage cases + one tuning proposal.

Module 5 — Detection engineering

Outcomes

  • start from a threat hypothesis;
  • define required telemetry;
  • implement or describe detection logic;
  • create test cases and false-positive guidance.

Assessment: Wazuh Detection Pack.

Module 6 — Incident response

Outcomes

  • classify incidents;
  • document containment, eradication and recovery options;
  • create decision logs and stakeholder updates.

Assessment: incident tabletop and runbook.

Module 7 — Threat intelligence and MITRE ATT&CK

Outcomes

  • distinguish indicators, behaviours and techniques;
  • map relevant detections to ATT&CK;
  • assess source relevance and confidence.

Assessment: technique-to-telemetry matrix.

Module 8 — Cloud security fundamentals

Outcomes

  • explain shared responsibility, IAM, MFA, least privilege, logging, network exposure and monitoring;
  • compare equivalent security controls across cloud platforms;
  • identify cloud events relevant to SOC operations.

Assessment: cloud-security baseline and logging use case.

Module 9 — GitHub and evidence engineering

Outcomes

  • use issues, branches, commits and pull requests;
  • maintain clean README files and references;
  • avoid publishing secrets or sensitive evidence.

Assessment: reviewed portfolio repository.

Module 10 — Automation basics

Outcomes

  • automate one repetitive security-analysis task;
  • validate inputs and outputs;
  • document limitations and safe usage.

Assessment: Python or PowerShell utility with test evidence.

Module 11 — Professional communication

Outcomes

  • write concise incident summaries;
  • explain technical findings to non-technical audiences;
  • practise interview narratives linked to real evidence.

Assessment: one-page incident summary + mock interview.

Module 12 — Capstone

Outcomes

  • combine multiple evidence sources;
  • perform a complete triage/investigation/response workflow;
  • present conclusions and uncertainty clearly.

Assessment: multi-stage SOC case study.

Assessment rubric

DimensionWeight
Technical accuracy25%
Investigation logic20%
Evidence quality and reproducibility20%
Security/privacy discipline10%
Communication15%
Reflection and improvement10%

Pass: 75%
Distinction: 90%