top of page

EFFORT

4-8 WEEKS

40h trainer-led

FORMAT

Self-paced

or instructor-led

CERTIFIES

City & Guilds

Assured

PREREQUISITES

None

Basic networking knowledge, understanding of cybersecurity principles

For teams & organizations — volume pricing, instructor-led delivery, custom scenarios.

1,600

NX220 – SOC-Analyst

Valid for 6 months

// NX DEFENSE · LEVEL 3 · NX220

SOC Analyst

Monitor and defend network systems

Learn to operate a modern Security Operations Center using enterprise tools like Splunk and ELK Stack. From threat detection to incident response, master the skills needed to protect organizational assets.

Overview

This course trains security operations center (SOC) analysts to implement and maintain resilient SOC infrastructure through hands-on experience with industry-standard monitoring, detection, and response tools. Students learn system monitoring, incident response, threat hunting, and SIEM operations using platforms like Sysmon, ELK Stack, Splunk, and YARA. The course emphasizes practical application of the MITRE ATT&CK framework and development of incident response playbooks. Designed for aspiring and junior SOC analysts, the program covers the full spectrum of security operations from infrastructure setup through active threat hunting and incident management.

Learning Objectives

By the end of this course, students will be able to:

 

  • Configure and deploy Sysmon for comprehensive Windows system event logging and monitoring

  • Implement and manage firewall rules and NAT configurations using pfSense

  • Deploy and configure Snort-based intrusion detection and prevention systems with custom rulesets

  • Analyze security events and create custom queries using both ELK Stack and Splunk SIEM platforms

  • Apply the MITRE ATT&CK framework to guide threat hunting activities and identify adversary tactics

  • Perform advanced log analysis with filtering techniques to detect indicators of compromise

  • Develop and deploy YARA rules for malware identification and threat classification

  • Execute structured incident response procedures and develop actionable IR playbooks

Course Modules

  1. Event Analysis
    This module establishes foundational skills in monitoring and analyzing security events across enterprise environments. Students learn to identify meaningful patterns in system and network activity, distinguish normal behavior from anomalous events, and prioritize alerts for investigation. The module covers event correlation techniques and introduces the core concepts that underpin effective SOC operations.
     

  2. Firewalls
    Students install and configure pfSense firewall systems, learning to create and manage firewall rules that balance security requirements with business needs. The module covers NAT implementation, packet filtering, and advanced features like package management for enhanced security control. Practical exercises focus on designing rule sets that protect network perimeters while enabling legitimate traffic flow.
     

  3. IDS/IPS
    This module covers the deployment and configuration of Snort-based intrusion detection and prevention systems. Students learn to write and tune detection rules, configure inline blocking capabilities, and integrate IDS/IPS with broader security infrastructure. The training emphasizes real-time monitoring, signature-based and anomaly-based detection methods, and reducing false positives while maintaining high detection rates.
     

  4. Domain Events
    Students work with Windows Server environments, Active Directory Domain Services, and domain protocols to understand enterprise authentication and authorization mechanisms. The module covers Group Policy management, domain controller operations, and Windows event logging. Students learn to use tools like Wireshark for protocol analysis and gain visibility into domain-level security events that are critical for detecting lateral movement and privilege escalation.
     

  5. SIEM
    This module introduces Security Information and Event Management platforms with a focus on the ELK Stack (Elasticsearch, Logstash, Kibana). Students learn to aggregate logs from multiple sources, normalize data for analysis, and build visualizations for security monitoring. The training covers index management, data parsing with Logstash, and creating Kibana dashboards that provide real-time visibility into security posture.
     

  6. MITRE ATT&CK
    Students learn to leverage the MITRE ATT&CK framework as a structured knowledge base of adversary tactics, techniques, and procedures. The module covers mapping observed behaviors to ATT&CK techniques, using the framework to guide threat hunting activities, and developing detection strategies aligned with common attack patterns. This knowledge enables analysts to think like adversaries and anticipate attack progression.
     

  7. Log Analysis
    This module develops advanced log analysis skills for identifying security threats across diverse data sources including network devices, servers, and security appliances. Students learn filtering techniques to efficiently process large volumes of log data, extract relevant indicators, and correlate events across multiple systems. The training emphasizes practical application of log analysis in real-world threat detection scenarios.
     

  8. Splunk
    Students master Splunk's Search Processing Language (SPL) to create complex queries for security event analysis. The module covers Splunk's interface, dashboard creation, alert configuration, and integration with security workflows. Students learn to extract meaningful insights from diverse data sources, build saved searches for recurring investigations, and configure alerts that enable proactive threat detection and rapid incident response.
     

  9. Threat Hunting
    This module covers proactive threat hunting methodologies including hypothesis-driven investigations and indicator-based searches. Students configure Sysmon XML settings to capture relevant system events, analyze process creation chains and network connections, and develop YARA rules for malware identification. The training emphasizes hunting for sophisticated threats that evade traditional detection methods, using tools and techniques that complement automated security controls.
     

  10. Incident Response
    Students learn the complete incident response lifecycle: preparation, identification, containment, eradication, recovery, and lessons learned. The module focuses on developing clear, actionable IR playbooks for common incident types including malware infections, data breaches, and insider threats. Students practice coordinating response activities, documenting incidents, and conducting post-incident analysis to improve future response capabilities and organizational resilience.

// Where you'll do all of this

You won't watch this.

You'll run it live.

Every module above is executed inside Cyberium Arena — real tools on real nodes, deployed on the live internet, with live threat intelligence running from your first login. Not a sandbox. Not a VM. Not a video.

Live Internet

Real Tools

Sand Box

VM

Cyberium2_Login.png
Cyberium2_Student_1.png
Cyberium2_Training_Stats.png
Cyberium2_Specto_Cases.png

Delivery and Assessment

The course combines hands-on labs with real-world scenarios covering SOC infrastructure deployment, SIEM operations, and active threat hunting exercises. Students work with production-grade tools including pfSense, Snort, ELK Stack, Splunk, Sysmon, and YARA in simulated enterprise environments. Practical assessments evaluate the ability to detect threats, analyze security events, and execute incident response procedures.

Certification

Certificate of completion. This course prepares students for the ThinkCyber SOC Analyst certification, accredited by City & Guilds.

1,600

NX220 – SOC-Analyst

Valid for 6 months

Ready when you are

Trusted since 2016 — national police, military cyber units & Fortune 500 teams · City & Guilds Assured

bottom of page