Skip to content
Lyon & Fiurex
← Select your course
Tier I

SOC Tier I

Foundational SOC analyst training: frameworks, threat intelligence, traffic analysis, endpoint monitoring, SIEM, forensics, and phishing.

Select your module(s)

You can select the modules you want to learn. There's a recommended order in the learning curve, unless you already know something and want to go further.

1
Cyber Defense Frameworks
Hours: 6 hours
$257.58 USD/mo

Discover frameworks and policies that help establish a good security posture. Learn how organisations use these in defensive strategies.

  • Junior Security Analyst Intro — Play through a day in the life of a Junior Security Analyst, their responsibilities and qualifications needed to land a role as an analyst.
  • Pyramid Of Pain — Learn what is the Pyramid of Pain and how to utilize this model to determine the level of difficulty it will cause for an adversary to change the indicators associated with them, and their campaign.
  • Cyber Kill Chain — The Cyber Kill Chain framework is designed for identification and prevention of the network intrusions. You will learn what the adversaries need to do in order to achieve their goals.
  • Unified Kill Chain — The Unified Kill Chain is a framework which establishes the phases of an attack, and a means of identifying and mitigating risk to IT assets.
  • Diamond Model — Learn about the four core features of the Diamond Model of Intrusion Analysis: adversary, infrastructure, capability, and victim.
  • MITRE — This room will discuss the various resources MITRE has made available for the cybersecurity community.
2
Cyber Threat Intelligence
Hours: 12 hours
$658.27 USD/mo

Learn about identifying and using available security knowledge to mitigate and manage potential adversary actions.

  • Intro to Cyber Threat Intel — Introducing cyber threat intelligence and related topics, such as relevant standards and frameworks.
  • Threat Intelligence Tools — Explore different OSINT tools used to conduct security threat assessments and investigations.
  • Yara — Learn the applications and language that is Yara for everything threat intelligence, forensics, and threat hunting!
  • OpenCTI — Provide an understanding of the OpenCTI Project
  • MISP — Walkthrough on the use of MISP as a Threat Sharing Platform
3
Network Security and Traffic Analysis
Hours: 28 hours
$1,287.92 USD/mo

Understand the core concepts of Network Security and Traffic Analysis to spot and probe network anomalies using industry tools and techniques.

  • Traffic Analysis Essentials — Learn Network Security and Traffic Analysis foundations and take a step into probing network anomalies.
  • Snort — Learn how to use Snort to detect real-time threats, analyse recorded traffic files and identify anomalies.
  • Snort Challenge - The Basics — Put your snort skills into practice and write snort rules to analyse live capture network traffic.
  • Snort Challenge - Live Attacks — Put your snort skills into practice and defend against a live attack
  • NetworkMiner — Learn how to use NetworkMiner to analyse recorded traffic files and practice network forensics activities.
  • Zeek — Introduction to hands-on network monitoring and threat detection with Zeek (formerly Bro).
  • Zeek Exercises — Put your Zeek skills into practice and analyse network traffic.
  • Brim — Learn and practice log investigation, pcap analysis and threat hunting with Brim.
  • Wireshark: The Basics — Learn the basics of Wireshark and how to analyse protocols and PCAPs.
  • Wireshark: Packet Operations — Learn the fundamentals of packet analysis with Wireshark and how to find the needle in the haystack!
  • Wireshark: Traffic Analysis — Learn the basics of traffic analysis with Wireshark and how to find anomalies on your network!
4
Endpoint Security Monitoring
Hours: 14 hours
$772.75 USD/mo

Monitoring activity on workstations is essential, as that's where adversaries spend the most time trying to achieve their objectives.

  • Intro to Endpoint Security — Learn about fundamentals, methodology, and tooling for endpoint security monitoring.
  • Core Windows Processes — Explore the core processes within a Windows operating system and understand what normal behaviour is. This foundational knowledge will help you identify malicious processes running on an endpoint!
  • Sysinternals — Learn to use the Sysinternals tools to analyze Windows systems or applications.
  • Windows Event Logs — Introduction to Windows Event Logs and the tools to query them.
  • Sysmon — Learn how to utilize Sysmon to monitor and log your endpoints and environments.
  • Osquery: The Basics — Let's cover the basics of Osquery.
  • Wazuh — Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring.
5
Security Information and Event Management (SIEM)
Hours: 14 hours
$772.75 USD/mo

Understand how SIEM works and get comfortable creating simple and advanced search queries to look for specific answers from the ingested logs.

  • Introduction to SIEM — An introduction to Security Information and Event Management.
  • Investigating with ELK 101 — Investigate VPN logs through ELK.
  • ItsyBitsy — Put your ELK knowledge together and investigate an incident.
  • Splunk: Basics — Learn the basics of Splunk.
  • Incident handling with Splunk — Learn to use Splunk for incident handling through interactive scenarios.
  • Investigating with Splunk — Investigate anomalies using Splunk.
  • Benign — Challenge room to investigate a compromised host.
6
Digital Forensics and Incident Response
Hours: 48 hours
$1,431.02 USD/mo

Understand what forensic artifacts are present in the Windows and Linux Operating Systems, how to collect them, and leverage them to investigate security incidents.

  • DFIR: An Introduction — Introductory room for the DFIR module
  • Windows Forensics 1 — Introduction to Windows Registry Forensics
  • Windows Forensics 2 — Learn about common Windows file systems and forensic artifacts in the file systems.
  • Linux Forensics — Learn about the common forensic artifacts found in the file system of Linux Operating System
  • Autopsy — Learn how to use Autopsy to investigate artefacts from a disk image. Use your knowledge to investigate an employee who is being accused of leaking private company data.
  • Redline — Learn how to use Redline to perform memory analysis and to scan for IOCs on an endpoint.
  • KAPE — An introduction to Kroll Artifact Parser and Extractor (KAPE) for collecting and processing forensic artifacts
  • Volatility — Learn how to perform memory forensics with Volatility!
  • Velociraptor — Learn Velociraptor, an advanced open-source endpoint monitoring, digital forensic and cyber response platform.
  • TheHive Project — Learn how to use TheHive, a Security Incident Response Platform, to report investigation findings
  • Intro to Malware Analysis — What to do when you run into a suspected malware
7
Phishing
Hours: 4 hours
$286.20 USD/mo

Learn how to analyze and defend against phishing emails. Investigate real-world phishing attempts using a variety of techniques.

  • Phishing Analysis Fundamentals — Learn all the components that make up an email.
  • Phishing Emails in Action — Learn the different indicators of phishing attempts by examining actual phishing emails.
  • Phishing Analysis Tools — Learn the tools used to aid an analyst to investigate suspicious emails.
  • Phishing Prevention — Learn how to defend against phishing emails.
  • The Greenholt Phish — Use the knowledge attained to analyze a malicious email.

Includes Lab practices. All prices are monthly (MXN), before taxes.

Plan your training path

Tell us your team, schedule and modules of interest and we will reply with the next steps.

Request information

Online enrollment is coming soon. In the meantime, contact us to enroll.