SOC Analyst Course Syllabus

The full module breakdown for the Techonquer Certified SOC Analyst program. Built around what an L1 and L2 analyst actually does on shift, not around a vendor product tour.

Before you commit, read what a SOC analyst actually does all day and SOC analyst salary in India, both honest about the shift work.

Module 1: Security Operations Foundations

  • How a SOC is structured: L1, L2, L3 and specialist roles
  • Networking and protocol fundamentals for defenders
  • Windows and Linux internals relevant to detection
  • The attacker lifecycle and why defenders need to understand it

Module 2: Log Analysis

  • Windows event logs: the event IDs that matter and what normal looks like
  • Linux system and authentication logs
  • Firewall, proxy and DNS logs
  • Application and web server logs
  • Log normalisation and parsing

Module 3: SIEM Operations

  • SIEM architecture and data flow
  • Query languages and building efficient searches
  • Dashboards and correlation rules
  • Alert tuning and false positive reduction
  • Hands on with an open source SIEM you can keep running after the course

Module 4: Alert Triage

  • Working the queue: classify, escalate or close
  • Enrichment: what to check before escalating
  • Threat intelligence and indicator lookup
  • Documenting a triage decision so the next analyst can follow it

Module 5: Detection Engineering

The module that separates an L2 from an L1, and the clearest pay premium in blue team work.

  • Writing detection rules rather than consuming alerts
  • Mapping detections to attacker techniques
  • Testing detections against generated telemetry
  • Measuring detection coverage and finding the gaps

Module 6: Incident Response

  • The incident response lifecycle
  • Containment decisions and their trade offs
  • Evidence preservation and chain of custody
  • Malware triage basics
  • Ransomware response in the first hour
  • Post incident review

Module 7: Threat Hunting

  • Hypothesis driven hunting versus alert driven response
  • Building a hunt from a technique rather than an indicator
  • Turning a successful hunt into a permanent detection

Module 8: Reporting and Communication

  • Writing an incident report an executive will act on
  • Shift handover documentation
  • Metrics that actually mean something

Tools covered

AreaTools
SIEMWazuh, with concepts transferable to Splunk and QRadar
Endpoint telemetrySysmon, native Windows logging
TrafficWireshark, Zeek concepts
AnalysisThreat intelligence platforms, sandbox triage
AutomationPython and PowerShell for analyst workflow

Assessment

  • Live triage exercises against generated attack telemetry
  • One detection rule you write, test and document
  • One full incident report
  • Seventy percent attendance required for certification

Build the lab free

Hacklido has free practical challenges. Building your own SIEM lab and writing detections for telemetry you generated answers most L1 interview questions before they are asked.

Enrol in the SOC Analyst program

Verify every module below against your actual delivered curriculum before publishing. A syllabus page that does not match what you teach is a refund request waiting to happen.

Frequently asked questions

Is the SOC course suitable for freshers?

Yes. Module 1 covers networking, Windows and Linux fundamentals for defenders from scratch. Most SOC hiring in India is at L1, which is the tier this program targets.

Which SIEM is taught?

Wazuh, which is free and open source so you keep your lab after the course. The query and correlation concepts transfer directly to Splunk and QRadar.

Does the course cover detection engineering?

Yes, as a dedicated module. Writing and testing your own rules is the clearest pay premium in blue team work and the main route from L1 to L2.

Will I have to work night shifts as a SOC analyst?

At L1 and often L2 in India, yes, because a SOC runs around the clock. L3, detection engineering and specialist roles are typically business hours.

Is SOC or penetration testing better to start with?

SOC has more openings in India and a lower entry bar, with lower starting pay and a clearer progression ladder. Penetration testing pays more at entry and is harder to enter.

Is a certificate provided?

Yes, with a unique public verification ID, subject to seventy percent attendance and completion of the practical assessments.