CLS
Cybersecurity

Certified SOC Analyst (CSA) - EC-Council

The Certified SOC Analyst CSA provides training and certification in the fundamental principles and practices of security operations, threat intelligence, and incident response.

Total Duration
24 Hours
Level
Intermediate
Category
Cybersecurity
Partner
EC-Council
About this course

About this course

The CSA training program covers topics include the following: attack techniques, security tools and methodologies, SIEM, incident response, and SOC development.

Students gain the ability to incident triage, indicators of compromise and the cyber kill chain, thus equipping them to take proactive measures against any possible attacks. In addition, they will be able to identify new attack patterns, develop correlation rules, and create effective reports that help organizations maintain a robust security posture.

Target Audience

Aspiring SOC Analysts who want to start their cybersecurity career
IT professionals looking to transition into SOC and defensive security roles
Cybersecurity professionals who want to strengthen their threat detection and monitoring skills
Incident response and threat detection professionals looking to build stronger SOC capabilities
Professionals preparing for the Certified SOC Analyst (CSA) certification

Prerequisites

Experience in the cybersecurity domain is recommended

Course Outline

Learn how a SOC enhances an organization’s security management to maintain a strong security posture, focusing on the critical roles of people, technology, and processes in its operations.
Learn various cyberattacks, their IoCs, and the attack tactics, techniques, and procedures (TTPs) cybercriminals use.
Learn log management in SIEM, including how logs are generated, stored, centrally collected, normalized, and correlated across systems.
Learn SIEM fundamentals, including its capabilities, deployment strategies, use case development, and how it helps SOC analysts detect anomalies, triage alerts, and report incidents.
Learn the importance of threat intelligence and threat hunting for SOC analysts and how its integration with SIEM helps reduce false positives and enables faster, more accurate alert triage.
Learn the stages of incident response and how the IRT collaborates with SOC to handle and respond to escalated incidents.
Learn the importance of forensic investigation and malware analysis in SOC operations to understand attack methods, identify IoCs, and enhance future defenses.
Learn the SOC processes in cloud environments, covering monitoring, incident detection, automated response, and security in AWS, Azure and GCP
Learning outcomes

What you'll learn

Gain a solid knowledge base on security threats, attacks, vulnerabilities, attacker behavior, and the cyber kill chain.
The ability to detect attacker TTPs and indicators of compromise (IoCs) for both current and future security investigations.
The ability to operate and administer SIEM solutions, e.g., Splunk, AlienVault, OSSIM, and the ELK Stack.
Architecture, deployment, tuning, and optimization of SIEM solutions.
Hands-on experience with the SIEM use case development process.
The ability to build threat detection cases (correlation rules), generate and produce reports.
The knowledge of common use cases of SIEM solutions in various deployments.
Acquire skills to monitor emerging threat patterns and perform security threat analysis.
Learn about using continuously emerging sources of threat intelligence.
Learn about the process of incident response and proper handling of security incidents.
Learn about the collaboration between SOC and Incident Response Team (IRT).

Skills you'll learn

15 skills
SOC Operations
Threat Analysis
Attack Analysis
SIEM Administration
SIEM Architecture
Threat Monitoring
Incident Tracking
Threat Intelligence
Incident Response
Forensic Analysis

Certificate

  • Attendance Certificate from CLS Learning Solutions
  • This course enables you to pass Certified SOC Analyst (CSA) Exam
Certified SOC Analyst (CSA) - EC-Council

Potential Career Paths

Junior SOC Security Analyst
SOC Analyst
Security Incident Response Analyst
SOC Threat Analyst
Info Security Analyst