Home/Training/Certified SOC Analyst

Programme Detail

Certified SOC Analyst

The Certified SOC Analyst programme prepares learners for security-operations work involving log management, SIEM, alert triage, threat intelligence, incident...

Security OperationsRegistration Open

Programme overview

The Certified SOC Analyst programme prepares learners for security-operations work involving log management, SIEM, alert triage, threat intelligence, incident investigation, reporting, and threat hunting. It combines SOC processes with practical use of tools, indicators, attack frameworks, and automation. Participants will work with representative logs, alerts, intelligence, cases, and analyst workflows to improve monitoring, investigation, threat hunting, and reporting skills.

Programmes can be delivered via

HRD Corp Claimable
Yayasan Peneraju aligned
EC-Council

At a glance

Course code
EC-021
Provider
EC-Council
Category
Security Operations
Status
Registration Open
Duration
3 days
Price
RM 4,700

What participants should gain

  • Explain SOC roles, processes, architecture, and maturity
  • Collect, normalise, and analyse security logs
  • Configure SIEM use cases and investigate alerts
  • Triage incidents using indicators, attack frameworks, and threat intelligence
  • Create clear incident reports and support threat hunting

Participant readiness

  • Basic knowledge of networking, operating systems, and cybersecurity
  • Familiarity with logs and common attacks is beneficial
  • Suitable for aspiring SOC analysts, security analysts, and incident responders

Who this course is for

  • SOC analysts, threat-intelligence analysts, incident responders, and threat hunters
  • Security analysts responsible for monitoring, investigation, detection, or reporting
  • Cybersecurity professionals seeking structured blue-team and intelligence skills

How the course is delivered

This programme will be conducted through interactive lectures, SOC workflow demonstrations, log and alert analysis, guided investigations, threat-intelligence activities, case-management exercises, reporting, and knowledge checks.

This programme will be conducted through interactive lectures, SOC workflow demonstrations, log and alert analysis, guided investigations, threat-intelligence activities, case-management exercises, reporting, and knowledge checks | By enquiry

Course outline

Module and topic breakdown

Module 1: Security Operations Centre Fundamentals

Operational processes for monitoring, vulnerability management, incident response, and assurance

Module 2: Cyber Threats, Attack Vectors, and Attack Frameworks

Preconditions, attack paths, tools, techniques, and indicators associated with Cyber Threats, Attack Vectors, and Attack Frameworks

Module 3: Centralized Log Collection and Management

Events, logs, telemetry, sources, formats, timestamps, fields, context, and retention

Module 4: SIEM Architecture, Deployment, and Use Cases

Secure build artefacts, configuration, secrets, dependencies, environments, and release approvals

Module 5: Alert Monitoring, Triage, and Prioritization

Collection of logs, events, metrics, traces, alerts, and contextual asset data

Module 6: Indicators of Compromise and Threat Intelligence

Strategic, operational, tactical, and technical intelligence and their audiences

Module 7: Incident Investigation and Evidence Analysis

Evidence identification, relevance, authority, integrity, preservation, and documentation

Module 8: Threat Hunting and Behavioural Analytics

Establishing normal behaviour for users, entities, devices, applications, and networks

Module 9: AI-Enabled SOC Automation and Detection

Identifying repeatable tasks, inputs, decisions, outputs, dependencies, and control points

Module 10: SOC Reporting, Metrics, and Continuous Improvement

Audience, purpose, scope, methodology, limitations, evidence, and executive summary

Assessment and completion

  • Continuous knowledge checks and facilitator feedback throughout the programme
  • Completion of guided exercises, scenarios, labs, or case-study activities applicable to the course
  • Final review or practical activity to confirm understanding of the stated course objectives
  • Official EC-Council examination and certification requirements depend on the selected training package and current exam version

Availability

This programme has a public intake path. Use the enquiry form below to confirm the next available session or a private cohort.

Programme enquiry

Discuss pricing, delivery, or corporate customisation

Use this form to confirm availability, request pricing clarification, or discuss a private cohort for your organisation.