TCM Security – SOC101
About
This course aims to equip students with all of the fundamental security operations knowledge and practical skills needed in order to achieve and excel in a T1 or T2 SOC Analyst position. By covering topics such as phishing analysis, incident response procedures, threat detection techniques, log analysis, SIEM management, and security tool utilization, students will gain the essential competencies required to effectively monitor, analyze, and respond to security incidents within a SOC environment.
Students will be able to actively engage with the course material through bite-sized video demonstrations, written materials and references, quizzes to assess comprehension, and practical exercises that simulate real-world scenarios.
By the end of the course, participants will be proficient in using various common security tools, analyzing security events and artifacts, handling alert tickets, triaging, and responding effectively to incidents within a SOC. Additionally, the course aims to foster critical thinking skills and encourage both proactive and reactive methodologies, which are pivotal for skilled analysts.
Objective
Objectives
- Learn the Foundations of Security Operations:
- Understand the foundational principles and practices of security operations.
- Analyze Phishing Attacks:
- Learn techniques for analyzing and identifying phishing attacks.
- Monitor Network Traffic:
- Develop skills in monitoring network traffic for security threats and anomalies.
- Analyze Security Events:
- Develop skills in monitoring and analyzing security events on individual hosts.
- How to Use a SIEM:
- Learn how to effectively use a SIEM for security event correlation, analysis, and incident management.
- Leveraging Threat Intelligence:
- Learn how to leverage threat intelligence to enhance security operations and incident response.
- Understand Digital Forensic Processes:
- Develop an understanding of digital forensics processes, common tools, and methodologies.
- Introduction to Incident Response:
- Understand the procedures, and best practices for incident response in a SOC environment.
Course Outline
- Introduction
- Lab Setup
- Security Operations Fundamentals
- SOC101 - Phishing Analysis
- Network Security
- Endpoint Security
- Security Information and Event Management (SIEM)
- Threat Intelligence
- Digital Forensics
- Incident Response
- Conclusion
- Course Wrap Up
- Next Steps: Practical SOC Analyst Associate (PSAA)
System Requirements
To get the most out of this course and follow along with the labs, there will be times where two virtual machines (VMs) need to be run simultaneously. If resources are limited, you can run one VM at a time and follow along with the course. Below are the recommended (ideal) specifications. Feel free to adjust based on your own system’s limitations, but these specs will ensure a smoother experience with the course labs.
Processor: 64-bit Intel i5 or i7, 2.0 GHz or higher.
RAM: At least 8 GB (ideally 8-12+ GB) to efficiently run multiple VMs.
Disk Space: 80-100 GB of free storage. SSDs are recommended for better performance.