SOC Analyst & SIEM Operations
Become a Tier-2 SOC Analyst by working with the same tools and workflows used in real Security Operations Centres. Learn to investigate alerts using Splunk, Microsoft Sentinel, and Elastic Security, write Sigma detection rules, correlate endpoint, network, and identity data, automate responses with SOAR playbooks, and create meaningful security reports.

Course Overview
Security Operations Centres (SOCs) play a critical role in detecting, investigating, and responding to cyber threats. This course prepares you for a Tier-2 SOC Analyst role by providing hands-on experience with leading SIEM platforms, including Splunk, Microsoft Sentinel, and Elastic Security.
You'll learn how a SOC operates, understand analyst workflows, shift handovers, and key performance metrics such as MTTA and MTTR. The course covers how security data from endpoints, networks, identities, cloud services, and SaaS applications is collected and analyzed to identify potential threats.
A strong emphasis is placed on detection engineering and incident investigation. You'll create Sigma detection rules mapped to the MITRE ATT&CK framework, convert them into Splunk SPL and Microsoft Sentinel KQL using pySigma, investigate alerts by correlating data from multiple sources, and document findings for incident response teams.
What you will learn
- Operate a Tier-2 SOC queue across Splunk, Microsoft Sentinel and Elastic Security
- Triage alerts
- Sigma detection rules for common attacker techniques
- Investigate incidents at Tier-2 depth
- Author SOAR playbooks
- Report SOC metrics
- Coordinate a cross-functional incident
Course Structure
A modular learning path with theory, hands-on labs, and progressive skill checkpoints.
- Module 01SOC Operating Model
- Module 02Telemetry Sources & Sensors
- Module 03SIEM Architecture (Splunk/Sentinel/ELK)
- Module 04Alert Triage Methodology
- Module 05Sigma Rule Authoring
Secure your Completion Certificate
- Industry-recognized — issued under the Cyberyami program.
- Shareable directly to LinkedIn and beyond.
- Unique ID for employer verification.

Tools & Technologies Covered
The production-grade tools you'll work with across labs and projects.
- Splunk Enterprise 9.x (primary lab SIEM)
- Microsoft Sentinel
- Elastic Security (ELK stack)
- Sigma (open detection format)
- pySigma / sigma-cli (translation toolchain)
- YARA (supplementary)
- SigmaHQ rules repository
- Sysmon with Olaf Hartong configuration
- Windows Event Log
- Splunk SOAR
- Wireshark
- Zeek (Bro) for network telemetry
- KQL & SPL query languages
- AWS
- Kali Linux
- Git + GitHub
- MITRE ATT&CK framework
Get Started
- Duration: 23
- Level: Intermediate
- Globally Recognized Curriculum
Hands-on training, real-world labs, and mentor support — built to take you from curious to job-ready.