SOC Operations & Threat Hunting (Blue Team)
Real-time SIEM log analysis with Splunk, MITRE ATT&CK mapping, memory forensics, and PCAP incident triage.
Course Overview & Objectives
Train as an enterprise SOC Analyst. Learn how to ingest multi-source telemetries into Splunk, build automated correlation rules, investigate live ransomware outbreaks, and execute structured threat hunting using the MITRE ATT&CK framework.
What You Will Master
- Operate Splunk Enterprise SIEM for real-time alerting and incident investigation
- Map observed adversary behaviors to MITRE ATT&CK tactics and techniques
- Analyze Wireshark PCAPs to detect command-and-control (C2) beaconing and data exfiltration
- Perform volatility-based live memory forensics during simulated malware infections
Prerequisites
- Basic operating system concepts (Windows/Linux)
- Understanding of TCP/IP networking
Platforms & Tools Covered
Detailed Curriculum Modules
2 modules structured from foundational theory through complex adversarial execution.
SIEM Architecture & Splunk Fundamentals
Ingesting Windows Event Logs, Sysmon, and Linux auth telemetries into a distributed SIEM.
Network Traffic Analysis & PCAP Forensics
Uncovering encrypted malware beacons, DNS tunneling, and cleartext credential harvesting in PCAPs.
Hands-on Virtual Sandbox Labs
Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.
Splunk Ransomware Triage Challenge
Identify patient zero, infection vector, and lateral movement timeline in Splunk.
Memory Forensics with Volatility 3
Extract injected DLLs and malicious process trees from infected memory dumps.
Faculty & Lead Instructor
Direct weekly instruction, live office hours, and code-review feedback.
Vikramaditya Sharma
Thread Security EducationPrincipal SOC Engineer & Incident Commander
Former Lead Incident Responder managing 24/7 global defense operations, triage, and threat eradication.
Frequently Asked Questions
Everything you need to know about scheduling, cohort admissions, and lab access.
Will I learn how to use real enterprise SIEM tools?
Yes! You work directly inside a licensed enterprise Splunk environment with populated multi-gigabyte attack datasets.
What jobs does this qualify me for?
SOC Analyst Tier 1 & 2, Incident Responder, Threat Intelligence Analyst, and Junior Threat Hunter.
Ready to Master SOC Operations & Threat Hunting (Blue Team)?
Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.