Skip to main content
Training Program

SOC Analyst & SIEM Operations

Become a Tier-2 SOC Analyst by working with the same tools and workflows used in real Security Operations Centres. Learn to investigate alerts using Splunk, Microsoft Sentinel, and Elastic Security, write Sigma detection rules, correlate endpoint, network, and identity data, automate responses with SOAR playbooks, and create meaningful security reports.

23
intermediate
SOC Analyst & SIEM Operations — training course cover
Overview

Course Overview

Security Operations Centres (SOCs) play a critical role in detecting, investigating, and responding to cyber threats. This course prepares you for a Tier-2 SOC Analyst role by providing hands-on experience with leading SIEM platforms, including Splunk, Microsoft Sentinel, and Elastic Security.

You'll learn how a SOC operates, understand analyst workflows, shift handovers, and key performance metrics such as MTTA and MTTR. The course covers how security data from endpoints, networks, identities, cloud services, and SaaS applications is collected and analyzed to identify potential threats.

A strong emphasis is placed on detection engineering and incident investigation. You'll create Sigma detection rules mapped to the MITRE ATT&CK framework, convert them into Splunk SPL and Microsoft Sentinel KQL using pySigma, investigate alerts by correlating data from multiple sources, and document findings for incident response teams.

What you will learn
  • Operate a Tier-2 SOC queue across Splunk, Microsoft Sentinel and Elastic Security
  • Triage alerts
  • Sigma detection rules for common attacker techniques
  • Investigate incidents at Tier-2 depth
  • Author SOAR playbooks
  • Report SOC metrics
  • Coordinate a cross-functional incident
Curriculum

Course Structure

A modular learning path with theory, hands-on labs, and progressive skill checkpoints.

  1. Module 01SOC Operating Model
  2. Module 02Telemetry Sources & Sensors
  3. Module 03SIEM Architecture (Splunk/Sentinel/ELK)
  4. Module 04Alert Triage Methodology
  5. Module 05Sigma Rule Authoring
Credential

Secure your Completion Certificate

Cyberyami Verified
  • Industry-recognized — issued under the Cyberyami program.
  • Shareable directly to LinkedIn and beyond.
  • Unique ID for employer verification.
Sample certificate of completion for SOC Analyst & SIEM Operations
Stack

Tools & Technologies Covered

The production-grade tools you'll work with across labs and projects.

  • Splunk Enterprise 9.x (primary lab SIEM)
  • Microsoft Sentinel
  • Elastic Security (ELK stack)
  • Sigma (open detection format)
  • pySigma / sigma-cli (translation toolchain)
  • YARA (supplementary)
  • SigmaHQ rules repository
  • Sysmon with Olaf Hartong configuration
  • Windows Event Log
  • Splunk SOAR
  • Wireshark
  • Zeek (Bro) for network telemetry
  • KQL & SPL query languages
  • AWS
  • Kali Linux
  • Git + GitHub
  • MITRE ATT&CK framework
  1. Duration: 23
  2. Level: Intermediate
  3. Globally Recognized Curriculum
Enrollment

Choose Your Training Path

Flexible learning modes designed to fit your schedule and learning style.

  • 25% OFF
    Training Mode

    Self Paced

    • Full course access available 24/7, on any device
    • Learn at your own pace with no fixed schedule
    • Hands-on labs in Cyberyami's browser-based virtual environment
    • Rewind, pause, and repeat lessons as often as needed
    • Practice assessments
    • Progress tracking to keep your learning on course
    • Lifetime or extended access to course materials and updates
  • 25% OFF
    Training Mode

    Instructor Led

    • Live sessions led by a certified, industry-experienced instructor
    • Real-time Q&A and doubt resolution during class
    • Fixed schedule that keeps you accountable and on track
    • Guided walkthroughs of complex labs and exam-style scenarios
    • Cohort-based learning with peer interaction and discussion
    • Session recordings available for revision
    • Direct mentorship and personalized exam-readiness guidance
  • 24% OFF
    Training Mode

    1 On 1

    • Dedicated one-on-one sessions with a certified, industry-experienced instructor
    • Personalized learning plan tailored to your goals, skill level, and schedule
    • Flexible class timings with the freedom to reschedule when needed
    • Individual attention with focused guidance on every concept and lab
    • Real-time Q&A and in-depth doubt resolution throughout the sessions
    • Customized hands-on lab walkthroughs based on your learning needs
    • Personalized feedback on assignments, assessments, and practical exercises
    • Exam-focused mentoring with a strategy designed for your certification goals
    • Career guidance, interview preparation, and industry best practices
Begin Today
Start your cybersecurity journey today!

Hands-on training, real-world labs, and mentor support — built to take you from curious to job-ready.