Certified SOC Analyst (CSA) Certification Training

BY
EC-Council via Infosec Train

Begin your journey towards a security operations centre (SOC) and become proficient in performing entry and intermediate-level operations with this training.

Lavel

Intermediate

Mode

Online

Quick Facts

particular details
Medium of instructions English
Mode of learning Self study, Virtual Classroom
Mode of Delivery Video and Text Based
Frequency of Classes Weekends

Course overview

The Certified SOC Analyst (CSA) Certification Training offered by Infosec Train has been designed to help you master in-demand and trending skills such as knowledge of SOC procedures, processes, workflows, and more. Also, it aims to provide detailed knowledge with a basic understanding of attacks, vulnerabilities, security threats, etc. Thus, it is a valuable training programme for both existing and aspiring tier 1 and 2 SOC analysts. 

Furthermore, the Certified SOC Analyst (CSA) Certification course offers enhanced level capabilities and in-depth knowledge for you to be able to contribute to a SOC team. The course has been curated to help you with basic SOC operations, SIEM deployment, log management, and advanced incident detection. You can also improve your knowledge of threat detection using the predictive capabilities of threat intelligence. 

The certification can act as your Launchpad and help demonstrate your skills and experience for the SOC Analyst job role. Through the SOC Analyst (CSA) Certification, you can secure a job in network security-related positions and obtain a high-paying job.

The highlights

  • Certified training experts
  • Proctored exam
  • 1-to-1 training
  • Instructor-led training
  • EC-Council Authorised Partner
  • Free demo class 
  • Training certificate
  • Technical support after training

Program offerings

  • Free demo class
  • Cei certified trainers
  • Corporate training
  • 1-to-1 training
  • Technical support post training
  • Certified instructors
  • Training certificate
  • Instructor-led training.

Course and certificate fees

certificate availability

Yes

certificate providing authority

EC-Council

Who it is for

The Certified SOC Analyst (CSA) Certification Training program caters to the following professionals:

  • Network and Security Engineers
  • L1/L2 SOC Analysts
  • Network Defence Analyst
  • Network Security Specialist
  • Network Defence Technicians
  • Cybersecurity professionals
  • Network and Security Administrators
  • Anyone aspiring to be a SOC analyst
  • Network Security Operator
  • Entry-level cybersecurity professionals

Eligibility criteria

To enroll in Infosec Train’s SOC Analyst certification programme, you must have a year of work experience in the security or network admin domain. But if you have attended official training, you don’t need the experience.

You must take the Certified SOC Analyst exam to qualify for the certificate. 

What you will learn

Knowledge of cyber security

Infosec Train’s Certified SOC Analyst (CSA) Certification syllabus will include the following: 

  • Incident response
  • The fundamentals of SOC
  • Incident detection using threat intelligence
  • Fundamentals of events, incidents, and logging
  • Understanding attack methodology, cyber threats, IoCs
  • Incident detection using Security Information and Event Management (SIEM) 

The syllabus

Module 1: Security Operations and Management

Key topics covered:
  • SOC, SOC Capabilities, SOC Operations, SOC Workflow, Components of SOC, SOC Models, SOC Maturity Models, SOC Generations, SOC KPIs and Metrics, SOC Challenges

Module 2: Understanding Cyber Threats, IoCs, and Attack Methodology

Key topics covered:
  • Cyber Threats, TTPs, Reconnaissance Attacks, Man-in-the-Middle Attacks, Password Attack
  • Techniques, Malware Attacks, Advanced Persistent Threat Lifecycle, Host-Based DoS Attacks,
  • Ransomware Attacks, SQL Injection Attacks, XSS Attacks, Cross-Site Request Forgery (CSRF)
  • Attack, Session Attacks, Social Engineering Attacks, Email Attacks, Insider Attacks, IoCs,
  • Attacker’s Hacking Methodology, MITRE D3FEND Framework, Diamond Model of Intrusion Analysis
Hands-on labs:
  • Perform SQL Injection Attack, Cross-Site Scripting (XSS) Attack, Network Scanning Attack, DoS Attack,
    and Brute Force Attack to understand their TTPs and IoCs.
  • Detect and analyze IoCs using Wireshark.

Module 3: Log Management

Key topics covered
  • Incident, Event, Log, Log Sources, Log Format, Local Logging, Windows Event Log, Linux Logs, Mac
    Logs, Firewall Logs, IP tables, Router Logs, IIS Logs, Apache Logs, Database Logs, Centralized
    Logging, Log Collection, Log Transmission, Log Storage, AI-Powered Script for Log Storage, Log
    Normalization, Log Parsing, Log Correlation, Log Analysis, Alerting and Reporting
Hands-on labs:
  • Configure, monitor, and analyze various logs.
  • Collect logs from different devices into a centralized location using Splunk.

Module 4: Incident Detection and Triage

Key topics covered:
  • SIEM, SIEM Architecture and its Components, AI-Enabled SIEM, Types of SIEM Solutions, SIEM Deployment, SIEM Use Cases, SIEM Deployment Architecture, SIEM Use Case Lifecycle,Application-Level Incident Detection SIEM Use Cases, Insider Incident Detection SIEM Use Cases,Examples of Network Level Incident Detection SIEM Use Cases, Examples of Compliance Use Cases,SIEM Rules Generation with AI, Alert Triage, Splunk AI, Elasticsearch AI, Alert Triage with AI,Dashboards in SOC, SOC Reports
Hands-on labs:
  • Develop Splunk use cases to detect and generate alerts for brute-force attempts, ransomware attacks, SQL injection attempts, XSS attempts, Broken Access Control attempts, application crashes using Remote Code Execution, scanning attempts, monitoring insecure ports and services, HTTP flood/denial of service (DoS) attacks, monitoring Windows audit log tampering, and malicious PowerShell script execution.
  • Enhance alert triage using the SIGMA rules for Splunk queries.
  • Create dashboards in Splunk.
  • Create ELK use cases for monitoring trusted binaries connecting to the internet, credential dumping using Mimikatz, and monitoring malware activity in the system.
  • Create dashboards in ELK.
  • Detect brute-force attack patterns using correlation rules in ManageEngine Log 360.

Module 5: Proactive Threat Detection

Key topics covered:
  • Cyber Threat Intelligence (CTI), Threat Intelligence Lifecycle, Types of Threat Intelligence,Threat Intelligence Strategy, Threat Intelligence Sources, Threat Intelligence Platform (TIP),Threat Intelligence-Driven SOC, Threat Intelligence Use Cases for Enhanced Incident Response,Enhanced Threat Detection with AI, Threat Hunting, Threat Hunting Process, Threat Hunting Frameworks, Threat Hunting with PowerShell Script, PowerShell AI Module, Threat Hunting with AI,Threat Hunting with YARA, Threat Hunting Tools
Hands-on labs:
  • Integrate IoCs into the ELK Stack.
  • Integrate OTX threat data into OSSIM.
  • Detects incidents in Windows Server using YARA.
  • Conduct threat hunting using Windows PowerShell scripts, Hunt Manager in Velociraptor, Log360 UEBA, and Sophos Central.

Module 6: Incident Response

Key topics covered:
  • Incident Response (IR), IRT, SOC and IRT Collaboration, IR Process, Ticketing System, Incident Triage, Notification, Containment, Eradication, Recovery, Network Security Incident Response,Application Security Incident Response, Email Security Incident Response, Insider Threats and Incident Response, Malware Threats and Incident Response, SOC Playbook, Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), SOAR, SOAR Playbook
Hands-on labs:
  • Generate tickets for incidents.
  • Contain data loss incidents.
  • Eradicate SQL injection and XSS incidents.
  • Perform recovery from data loss incidents.
  • Create incident reports using OSSIM.
  • Perform automated threat detection and response using Wazuh.
  • Detects threats using Sophos Central XDR.
  • Integrate Sophos Central XDR with Splunk.

Module 7: Forensic Investigation and Malware Analysis

Key topics covered:
  • Forensics Investigation, Forensics Investigation Methodology, Forensics Investigation Process,Forensics Investigation of Network Security Incidents, Forensics Investigation of Application Security Incidents, Forensics Investigation of Email Security Incidents, Forensics Investigation of Insider Incidents, Malware Analysis, Types of Malware Analysis, Malware Analysis Tools,Static Malware Analysis, Dynamic Malware Analysis
Hands-on labs:
  • Perform forensic investigation of application security incidents: SQL Injection Attacks.
  • Perform forensic investigation of a compromised system incident using Velociraptor.
  • Analyze RAM for suspicious activities using Redline.
  • Perform static analysis on a suspicious file using PeStudio.
  • Examine a suspicious file using VirusTotal.
  • Perform dynamic malware analysis in Windows using Process Hacker.

Module 8: SOC for Cloud Environments

Key topics covered:
  • Cloud SOC, Azure SOC Architecture, Microsoft Sentinel, AWS SOC Architecture, AWS Security Hub,Centralized Logging with OpenSearch, Google Cloud Platform (GCP) Security Operation Center,Security Command Center, Chronicle
Hands-on labs:
  • Implement Microsoft Sentinel in Azure.

Admission details

  • Go to the Certified SOC Analyst (CSA) Certification Training course web page 
  • You will find three available learning formats. Choose your preferred method and click the ‘Enroll Now’ option.
  • Fill in the details asked and submit the form.

Filling the form

To enter the Certified SOC Analyst (CSA) online course, fill in your full name, any active email address, phone number and your country in a pop-up form. Before submitting the form, enter a comment on the training you require.

Evaluation process

The Certified SOC Analyst (CSA) exam will consist of 100 MCQ questions and will have a duration of 180 minutes. 

How it helps

The SOC Analyst (CSA) certification can help you acquire in-demand skills trending in the current job market. Hence, you can secure a decent job in the field of network security and earn well. You will have an updated knowledge of the necessary skill set to become an L1/L2 SOC Analyst.

Instructors

Mr Abhy
Head of Security Testing
Freelancer

FAQs

Is work experience mandatory for this programme?

If you attend official training, you don’t require work experience to join.

Is it possible to get a physical copy of the certificate?

You can request a physical copy on the official site.

How long will the CSA certification be valid?

The SOC Analyst (CSA) certification will be valid for 3 years, starting from the date of passing your certification exam. 

How many questions will the Certified SOC Analyst (CSA) Certification exam have?

The Certified SOC Analyst (CSA) exam consists of 100 questions in an MCQ format.

What is the procedure to enrol in the demo class?

You must fill a small form by entering your name, contact no, email address, and a comment for the training. You must also mention whether you require the class for yourself or your company before answering a captcha question and reserving your seat.

Similar Courses

Information Security Design and Development

Coventry University, Coventry via Futurelearn

10 Weeks Online
Intermediate

Cyber Security Foundations Start Building Your Car...

EC-Council via Futurelearn

15 Weeks Online
Intermediate

Certificate in Cyber Security at Quality Licence S...

OHSC

200 Hours Online
Intermediate
£74 £185

Manage the Cyber Threat for Finance Professionals

ACCA via Edx

4 Weeks Online
Intermediate
Free

Information Security Introduction to Information S...

NYU via Edx

5 Weeks Online
Intermediate
Free

Certified Information Systems Security Professiona...

GreyCampus

Online
Intermediate
₹26,640 ₹29,600

Asymmetric Cryptography and Key Management

CU Boulder via Coursera

9 Hours Online
Intermediate

Check Point Jump Start Maestro Hyperscale Network ...

Check Point Software Technologies Limited via Coursera

4 Hours Online
Intermediate

Cyber-Physical Systems Modeling and Simulation

UC Santa Cruz via Coursera

1 Week Online
Intermediate

Information Security Advanced topics

NYU via Edx

5 Weeks Online
Intermediate
Free

Courses of your Interest

Introduction to Medical Software

Introduction to Medical Software

Yale University, New Haven via Coursera

4 Weeks Online
Intermediate
₹ 2,699

Google Cloud Architect Program

Google Cloud via SkillUp Online

11 Weeks Online
Intermediate
₹ 54,999

Google Cloud Architect Program

Google via SkillUp Online

11 Weeks Online
Intermediate
₹ 54,999
Ethics Laws and Implementing an AI Solution on Mic...

Ethics Laws and Implementing an AI Solution on Mic...

CloudSwyft Global Systems, Inc via Futurelearn

14 Weeks Online
Intermediate
Network Security and Defence

Network Security and Defence

Coventry University, Coventry via Futurelearn

10 Weeks Online
Intermediate
Data Science on Microsoft Azure Using Python Progr...

Data Science on Microsoft Azure Using Python Progr...

CloudSwyft Global Systems, Inc via Futurelearn

15 Weeks Online
Intermediate
Applied Data Analysis

Applied Data Analysis

CloudSwyft Global Systems, Inc via Futurelearn

14 Weeks Online
Intermediate
₹ 900
Advanced and Applied Artificial Intelligence on Mi...

Advanced and Applied Artificial Intelligence on Mi...

CloudSwyft Global Systems, Inc via Futurelearn

15 Weeks Online
Intermediate

Artificial Intelligence with Python

Great Learning

11 Hours Online
Intermediate
Free

Trending Courses

Popular Courses

Popular Platforms

Learn more about the Courses