SOC Analyst Course Syllabus
The full module breakdown for the Techonquer Certified SOC Analyst program. Built around what an L1 and L2 analyst actually does on shift, not around a vendor product tour.
Before you commit, read what a SOC analyst actually does all day and SOC analyst salary in India, both honest about the shift work.
Module 1: Security Operations Foundations
- How a SOC is structured: L1, L2, L3 and specialist roles
- Networking and protocol fundamentals for defenders
- Windows and Linux internals relevant to detection
- The attacker lifecycle and why defenders need to understand it
Module 2: Log Analysis
- Windows event logs: the event IDs that matter and what normal looks like
- Linux system and authentication logs
- Firewall, proxy and DNS logs
- Application and web server logs
- Log normalisation and parsing
Module 3: SIEM Operations
- SIEM architecture and data flow
- Query languages and building efficient searches
- Dashboards and correlation rules
- Alert tuning and false positive reduction
- Hands on with an open source SIEM you can keep running after the course
Module 4: Alert Triage
- Working the queue: classify, escalate or close
- Enrichment: what to check before escalating
- Threat intelligence and indicator lookup
- Documenting a triage decision so the next analyst can follow it
Module 5: Detection Engineering
The module that separates an L2 from an L1, and the clearest pay premium in blue team work.
- Writing detection rules rather than consuming alerts
- Mapping detections to attacker techniques
- Testing detections against generated telemetry
- Measuring detection coverage and finding the gaps
Module 6: Incident Response
- The incident response lifecycle
- Containment decisions and their trade offs
- Evidence preservation and chain of custody
- Malware triage basics
- Ransomware response in the first hour
- Post incident review
Module 7: Threat Hunting
- Hypothesis driven hunting versus alert driven response
- Building a hunt from a technique rather than an indicator
- Turning a successful hunt into a permanent detection
Module 8: Reporting and Communication
- Writing an incident report an executive will act on
- Shift handover documentation
- Metrics that actually mean something
Tools covered
| Area | Tools |
|---|---|
| SIEM | Wazuh, with concepts transferable to Splunk and QRadar |
| Endpoint telemetry | Sysmon, native Windows logging |
| Traffic | Wireshark, Zeek concepts |
| Analysis | Threat intelligence platforms, sandbox triage |
| Automation | Python and PowerShell for analyst workflow |
Assessment
- Live triage exercises against generated attack telemetry
- One detection rule you write, test and document
- One full incident report
- Seventy percent attendance required for certification
Build the lab free
Hacklido has free practical challenges. Building your own SIEM lab and writing detections for telemetry you generated answers most L1 interview questions before they are asked.
Enrol in the SOC Analyst program
Verify every module below against your actual delivered curriculum before publishing. A syllabus page that does not match what you teach is a refund request waiting to happen.
Frequently asked questions
Is the SOC course suitable for freshers?
Yes. Module 1 covers networking, Windows and Linux fundamentals for defenders from scratch. Most SOC hiring in India is at L1, which is the tier this program targets.
Which SIEM is taught?
Wazuh, which is free and open source so you keep your lab after the course. The query and correlation concepts transfer directly to Splunk and QRadar.
Does the course cover detection engineering?
Yes, as a dedicated module. Writing and testing your own rules is the clearest pay premium in blue team work and the main route from L1 to L2.
Will I have to work night shifts as a SOC analyst?
At L1 and often L2 in India, yes, because a SOC runs around the clock. L3, detection engineering and specialist roles are typically business hours.
Is SOC or penetration testing better to start with?
SOC has more openings in India and a lower entry bar, with lower starting pay and a clearer progression ladder. Penetration testing pays more at entry and is harder to enter.
Is a certificate provided?
Yes, with a unique public verification ID, subject to seventy percent attendance and completion of the practical assessments.