Course Curriculum
The curriculum is organised around employable SOC evidence rather than course completion.
Module 1 — SOC foundations
Outcomes
- explain SOC roles, alert lifecycle, severity, escalation and evidence handling;
- distinguish monitoring, detection, investigation and incident response;
- use an investigation template consistently.
Assessment: capability matrix + one triage record.
Module 2 — Networking for analysts
Outcomes
- reason about IP addresses, ports, protocols, DNS and TCP/UDP;
- interpret source/destination context;
- recognise common network evidence used in investigations.
Assessment: annotated network-flow analysis and packet/log notes.
Module 3 — Windows security telemetry
Outcomes
- use Event Viewer and Windows Security logs;
- interpret authentication activity and process evidence;
- create timelines and correlate related events.
Assessment: Event 4625 investigation pack.
Module 4 — Wazuh SIEM operations
Outcomes
- understand agent/manager/rule/alert relationships;
- triage alerts systematically;
- document rule tuning and false positives.
Assessment: three alert triage cases + one tuning proposal.
Module 5 — Detection engineering
Outcomes
- start from a threat hypothesis;
- define required telemetry;
- implement or describe detection logic;
- create test cases and false-positive guidance.
Assessment: Wazuh Detection Pack.
Module 6 — Incident response
Outcomes
- classify incidents;
- document containment, eradication and recovery options;
- create decision logs and stakeholder updates.
Assessment: incident tabletop and runbook.
Module 7 — Threat intelligence and MITRE ATT&CK
Outcomes
- distinguish indicators, behaviours and techniques;
- map relevant detections to ATT&CK;
- assess source relevance and confidence.
Assessment: technique-to-telemetry matrix.
Module 8 — Cloud security fundamentals
Outcomes
- explain shared responsibility, IAM, MFA, least privilege, logging, network exposure and monitoring;
- compare equivalent security controls across cloud platforms;
- identify cloud events relevant to SOC operations.
Assessment: cloud-security baseline and logging use case.
Module 9 — GitHub and evidence engineering
Outcomes
- use issues, branches, commits and pull requests;
- maintain clean README files and references;
- avoid publishing secrets or sensitive evidence.
Assessment: reviewed portfolio repository.
Module 10 — Automation basics
Outcomes
- automate one repetitive security-analysis task;
- validate inputs and outputs;
- document limitations and safe usage.
Assessment: Python or PowerShell utility with test evidence.
Module 11 — Professional communication
Outcomes
- write concise incident summaries;
- explain technical findings to non-technical audiences;
- practise interview narratives linked to real evidence.
Assessment: one-page incident summary + mock interview.
Module 12 — Capstone
Outcomes
- combine multiple evidence sources;
- perform a complete triage/investigation/response workflow;
- present conclusions and uncertainty clearly.
Assessment: multi-stage SOC case study.
Assessment rubric
| Dimension | Weight |
|---|---|
| Technical accuracy | 25% |
| Investigation logic | 20% |
| Evidence quality and reproducibility | 20% |
| Security/privacy discipline | 10% |
| Communication | 15% |
| Reflection and improvement | 10% |
Pass: 75%
Distinction: 90%