Welcome to Module One of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore Security Operations and Management. You will learn the principles, capabilities, and functions of a SOC, and how to manage SOC operations effectively.
Think of this module as understanding the engine room of cybersecurity defence. By the end of this module, you will understand how a SOC operates, how it evolves, and what makes it successful.
π‘ What you will learn: SOC principles, capabilities, and functions, SOC workflow and the People, Process, Technology framework, SOC models and maturity evolution, Key Performance Indicators (KPIs) and challenges, and best practices for effective SOC operations.
By the end of this module, you will be able to:
Amara was a Tier 1 SOC analyst at a bank in Lagos. She was good at her job, but she wanted to move up to Tier 2. She knew she needed to understand how the SOC operated as a whole.
She studied the People, Process, Technology framework. She learned about SOC maturity models and how to measure performance with KPIs. She also learned about common SOC challenges and how to overcome them.
Within a year, Amara was promoted to Tier 2 analyst. She now leads investigations and mentors junior analysts. She learned that understanding SOC operations is the foundation of a successful career.
Definition: A Security Operations Centre (SOC) is a centralized team responsible for monitoring, detecting, investigating, and responding to cybersecurity incidents.
Why it is important: The SOC is the heart of an organization's cybersecurity defence, providing 24/7 protection against threats.
π Mini summary: A SOC is a team that monitors, detects, and responds to cyber threats.
Definition: SOC principles are the foundational beliefs that guide SOC operations.
π Mini summary: SOC principles include proactive defence, continuous monitoring, rapid response, collaboration, and continuous improvement.
Definition: SOC capabilities are the things the SOC can do. Functions are the specific activities it performs.
π Mini summary: SOC capabilities include monitoring, detection, investigation, response, and recovery. Functions include alert triage, incident investigation, threat hunting, and reporting.
Definition: SOC workflow is the process of handling security events from detection to resolution.
π Mini summary: SOC workflow includes detection, triage, investigation, response, closure, and lessons learned.
Definition: The People, Process, Technology (PPT) framework is a model for building effective SOCs.
Analysts, managers, and leadership.
Procedures, workflows, and playbooks.
SIEM, EDR, SOAR, and other tools.
π Mini summary: The PPT framework consists of People (analysts), Process (procedures), and Technology (tools).
Definition: SOC models describe different ways to structure and operate a SOC.
π Mini summary: SOC models include internal, outsourced, hybrid, and federated.
Definition: SOC maturity describes how advanced a SOC is.
π Mini summary: SOC maturity evolves from reactive (Level 1) to proactive and optimized (Level 5).
Definition: KPIs are metrics used to measure SOC performance.
π Mini summary: KPIs like MTTD, MTTR, alert volume, false positive rate, and incident closure rate measure SOC performance.
Definition: SOC challenges are common problems that SOCs face.
π Mini summary: SOC challenges include alert fatigue, staff shortage, tool sprawl, budget constraints, and evolving threats.
Definition: Best practices are guidelines for effective SOC operations.
π Mini summary: Best practices for SOC operations include automation, measurement, training, integration, and staying updated.
Did you know? The Nigeria Data Protection Regulation (NDPR) requires organizations to protect personal data.
Did you know? SOCs use threat intelligence to stay ahead of attackers.
Did you know? Many SOCs are located in secure facilities to prevent physical attacks.
| Model | Description | Best for |
|---|---|---|
| Internal | Staffed by employees | Large enterprises |
| Outsourced | Managed by a third party | Small businesses |
| Hybrid | Combination of both | Flexible needs |
| Federated | Multiple SOCs working together | Large organizations |
| Level | Description | Characteristics |
|---|---|---|
| 1 β Initial | Reactive | Ad-hoc, no formal processes |
| 2 β Repeatable | Basic | Some processes in place |
| 3 β Defined | Formal | Standardized processes |
| 4 β Managed | Proactive | Automated and proactive |
| 5 β Optimized | Optimized | Continuous improvement |
Congratulations! You have completed Module One. You now know:
You are now ready to move on to Module Two, where you will learn about Cyber Threats, IoCs, and Attack Methodology.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. SOC | A. People, Process, Technology |
| 2. PPT | B. Security Operations Centre |
| 3. MTTD | C. Mean Time to Detect |
| 4. MTTR | D. Mean Time to Respond |
| 5. KPI | E. Key Performance Indicator |
Answers: 1-B, 2-A, 3-C, 4-D, 5-E
In groups of 3-4, research a real-world SOC. Present your findings to the class, including the SOC's structure, processes, and technologies.
Write a one-page report on the importance of SOC operations for an organization.
Project: "SOC Design." Design a SOC for a fictional organization. Include the SOC type, structure, processes, and technologies. Present your design to the class.
Research a real-world SOC. Write a one-page summary of its structure, processes, and technologies.
Research the NIST Cybersecurity Framework. Write a one-page summary of how it can be applied to a SOC.
Fill-in-the-Blank Answers:
True or False Answers: 1-T, 2-F, 3-T, 4-F, 5-F, 6-T, 7-F, 8-T, 9-T, 10-F
In Module Two, you will learn about Cyber Threats, IoCs, and Attack Methodology. You will explore threat actors, attack vectors, and the Cyber Kill Chain.
Welcome to Module Two of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore cyber threats, Indicators of Compromise (IoCs), and attack methodology. You will learn how to identify, classify, and respond to various types of cyber threats.
Think of this module as understanding the enemy. By the end of this module, you will be able to identify threats, understand attack patterns, and use IoCs to detect and respond to incidents.
π‘ What you will learn: Network, host, application, and social engineering TTPs, email and insider attack methodologies, Indicators of Compromise (IoCs) for various attacks, attack methodology and frameworks (Cyber Kill Chain, MITRE ATT&CK), and advanced adversary tactics and behaviours.
By the end of this module, you will be able to:
Chidi was a Tier 2 SOC analyst at a bank in Lagos. He received an alert about unusual network traffic. He started investigating and identified a potential ransomware attack.
He used the Cyber Kill Chain to map the attack stages. He identified the Indicators of Compromise (IoCs) and shared them with the team. He also used MITRE ATT&CK to understand the adversary's tactics and techniques.
His investigation helped the team contain the attack and prevent further damage. Chidi learned that understanding threats and IoCs is essential for effective incident response.
Definition: A cyber threat is any potential danger to an organization's information systems, networks, or data.
Why it is important: Understanding threats is the first step in protecting an organization.
π Mini summary: A cyber threat is any potential danger to information systems. Understanding threats is essential for protection.
Definition: Cyber threats can be classified into different categories.
Attacks on network infrastructure.
Attacks on individual systems.
Attacks on software applications.
Attacks that exploit human psychology.
Attacks delivered via email.
Attacks from within the organization.
π Mini summary: Types of cyber threats include network, host, application, social engineering, email, and insider threats.
Definition: Network threats are attacks on network infrastructure, such as routers, switches, and firewalls.
π Mini summary: Network threats target network infrastructure and include DoS, MitM, sniffing, and DNS spoofing.
Definition: Host threats are attacks on individual systems, such as desktops, servers, and laptops.
π Mini summary: Host threats target individual systems and include malware, unauthorized access, privilege escalation, and data theft.
Definition: Application threats are attacks on software applications, such as web applications and databases.
π Mini summary: Application threats target software applications and include SQL injection, XSS, CSRF, and buffer overflow.
Definition: Social engineering is the use of deception to manipulate people into divulging information or performing actions.
π Mini summary: Social engineering uses deception to manipulate people. Examples include phishing, pretexting, baiting, and tailgating.
Definition: Email threats are attacks delivered via email.
π Mini summary: Email threats include phishing, spear phishing, whaling, and business email compromise.
Definition: Insider threats are attacks from within the organization, such as employees or contractors.
π Mini summary: Insider threats come from within the organization and can be malicious, negligent, or compromised.
Definition: Indicators of Compromise (IoCs) are pieces of evidence that suggest a system has been compromised.
π Mini summary: IoCs are evidence of compromise and include file hashes, IP addresses, domain names, URLs, email addresses, and registry keys.
Definition: The Cyber Kill Chain is a model that describes the stages of a cyber attack.
π Mini summary: The Cyber Kill Chain describes the stages of an attack: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives.
Definition: MITRE ATT&CK is a knowledge base of adversary tactics and techniques.
π Mini summary: MITRE ATT&CK is a knowledge base of tactics and techniques used by adversaries.
Definition: Advanced adversaries use sophisticated tactics to evade detection.
π Mini summary: Advanced adversary tactics include living off the land, fileless malware, polymorphic malware, and APTs.
Did you know? MITRE ATT&CK is used by organizations worldwide to improve threat detection.
Did you know? The Cyber Kill Chain is based on military concepts.
Did you know? IoCs are often shared between organizations to improve security.
| Feature | Cyber Kill Chain | MITRE ATT&CK |
|---|---|---|
| Focus | Stages of an attack | Tactics and techniques |
| Structure | 7 stages | Matrix of tactics and techniques |
| Best for | Understanding attack progression | Threat detection and analysis |
| Type | Description | Examples |
|---|---|---|
| Network | Attacks on infrastructure | DoS, MitM |
| Host | Attacks on individual systems | Malware, unauthorized access |
| Application | Attacks on software | SQL injection, XSS |
| Social Engineering | Manipulating people | Phishing, pretexting |
| Attacks via email | Phishing, BEC | |
| Insider | Attacks from within | Malicious, negligent |
Congratulations! You have completed Module Two. You now know:
You are now ready to move on to Module Three, where you will learn about Advanced Log Management and Analysis.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. Network Threat | A. Attacks on individual systems |
| 2. Host Threat | B. Attacks on network infrastructure |
| 3. Application Threat | C. Attacks using deception |
| 4. Social Engineering | D. Attacks on software applications |
| 5. Insider Threat | E. Attacks from within the organization |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
In groups of 3-4, research a recent cyber attack. Identify the threat type, IoCs, and map the attack to the Cyber Kill Chain. Present your findings to the class.
Write a one-page report on a recent cyber threat. Include the threat type, IoCs, and attack methodology.
Project: "Threat Intelligence Report." Create a threat intelligence report on a recent cyber attack. Include the threat type, IoCs, attack methodology, and recommendations. Present your report to the class.
Identify IoCs for a recent cyber attack. Document your findings and create a report.
Research a real-world APT campaign. Map the attack to the Cyber Kill Chain and MITRE ATT&CK. Write a one-page summary of your findings.
Fill-in-the-Blank Answers:
True or False Answers: 1-T, 2-F, 3-F, 4-T, 5-T, 6-T, 7-F, 8-T, 9-F, 10-T
In Module Three, you will learn about Advanced Log Management and Analysis. You will explore local logging practices, centralised logging, and statistical analysis.
Welcome to Module Three of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore advanced log management and analysis. You will learn how to collect, manage, and analyze logs from various sources to detect threats.
Think of this module as learning the language of your systems. Logs are the digital footprints left by users, applications, and systems. By the end of this module, you will be able to analyze logs to identify malicious activity.
π‘ What you will learn: Log management importance and approaches, local logging practices (Windows, Linux, Mac), firewall, router, web server, database, and email logs, centralised logging implementation, and statistical and behavioural anomaly detection.
By the end of this module, you will be able to:
Kemi was a Tier 2 SOC analyst at a bank in Lagos. She received an alert about unusual network activity. She started analyzing logs from the firewall, web server, and database.
She identified a pattern of suspicious requests to the web server. She used statistical analysis to detect anomalies and identified a potential SQL injection attack. Her quick analysis helped the team block the attack.
Kemi learned that log analysis is essential for detecting and responding to threats. She now uses logs to investigate every incident.
Definition: Log management is the process of collecting, storing, and analyzing logs from various sources.
Why it is important: Logs provide a record of activity on systems and networks, making them essential for detecting and investigating threats.
π Mini summary: Log management is the process of collecting, storing, and analyzing logs to detect threats.
Definition: There are different approaches to log management.
π Mini summary: Log management approaches include centralized, distributed, and hybrid.
Definition: Windows provides several logging mechanisms, including Event Logs, Sysmon, and PowerShell logs.
π Mini summary: Windows logging includes Event Logs, Sysmon, and PowerShell logs.
Definition: Linux provides several logging mechanisms, including syslog, rsyslog, and auditd.
π Mini summary: Linux logging includes syslog, rsyslog, and auditd.
Definition: Mac provides logging mechanisms through the unified logging system.
π Mini summary: Mac logging includes unified logging, ASL, and the Console app.
Definition: Firewall logs record traffic that passes through a firewall.
π Mini summary: Firewall logs record traffic and can reveal blocked traffic, port scanning, and malicious IPs.
Definition: Router logs record activity on network routers.
π Mini summary: Router logs can reveal routing changes, interface errors, and suspicious logins.
Definition: Web server logs record requests to web servers.
π Mini summary: Web server logs can reveal 404 errors, SQL injection attempts, XSS attempts, and unusual user agents.
Definition: Database logs record activity on databases.
π Mini summary: Database logs can reveal failed logins, large queries, SQL injection, and privilege changes.
Definition: Email logs record email traffic and activity.
π Mini summary: Email logs can reveal spam, phishing, bounce errors, and suspicious logins.
Definition: Centralised logging is the process of sending logs from multiple sources to a central server.
π Mini summary: Centralised logging collects logs from multiple sources to a central server for easier analysis and correlation.
Definition: Anomaly detection identifies unusual patterns in logs.
π Mini summary: Statistical and behavioural anomaly detection identifies unusual patterns in logs using baselines, thresholds, and behavioural analysis.
Did you know? Logs can be used to detect insider threats.
Did you know? Centralised logging improves security by protecting logs.
Did you know? Anomaly detection can identify zero-day attacks.
| Feature | Centralised | Distributed |
|---|---|---|
| Log location | Central server | Local systems |
| Analysis | Easier | Harder |
| Security | Higher | Lower |
| Best for | Large organizations | Small organizations |
| Source | Description | Key Insights |
|---|---|---|
| Firewall | Traffic records | Blocked traffic, port scanning |
| Router | Network activity | Routing changes, interface errors |
| Web Server | Web requests | 404 errors, SQL injection |
| Database | Database activity | Failed logins, large queries |
| Email traffic | Spam, phishing |
Congratulations! You have completed Module Three. You now know:
You are now ready to move on to Module Four, where you will learn about Incident Detection with SIEM.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. Centralised Logging | A. Logs stored locally |
| 2. Distributed Logging | B. Logs sent to a central server |
| 3. syslog | C. Linux logging system |
| 4. Sysmon | D. Windows monitoring tool |
| 5. auditd | E. Linux audit system |
Answers: 1-B, 2-A, 3-C, 4-D, 5-E
In groups of 3-4, set up a centralised logging environment using ELK Stack or Graylog. Collect logs from multiple sources and create dashboards. Present your setup to the class.
Write a one-page report on a log analysis tool of your choice (ELK Stack, Splunk, or Graylog). Include its features and use cases.
Project: "Log Management Implementation." Implement a centralised logging solution for a fictional organization. Include log collection, analysis, and dashboards. Present your solution to the class.
Set up a centralised logging environment using ELK Stack or Graylog. Collect logs from at least two sources. Create a dashboard to visualize the logs.
Research the differences between ELK Stack and Splunk. Write a one-page summary of the differences and which is better for specific use cases.
Fill-in-the-Blank Answers:
True or False Answers: 1-F, 2-T, 3-F, 4-T, 5-T, 6-F, 7-T, 8-F, 9-F, 10-T
In Module Four, you will learn about Incident Detection with SIEM. You will explore SIEM architecture, deployment, and use case management.
Welcome to Module Four of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore incident detection with SIEM. You will learn how to deploy and use SIEM (Security Information and Event Management) systems to detect and respond to threats.
Think of SIEM as the brain of the SOC. It collects, analyzes, and correlates logs from various sources to identify threats. By the end of this module, you will be able to configure and use SIEM for incident detection.
π‘ What you will learn: SIEM architecture and importance, SIEM solutions (advantages and disadvantages), SIEM deployment and use case management, incident detection with SIEM, AI for generating SIEM rules, alert triaging, correlation, multi-domain event detection, visualization, dashboard management, and SOC reports.
By the end of this module, you will be able to:
Amara was a Tier 2 SOC analyst at a bank in Lagos. She was tasked with deploying a SIEM solution to improve threat detection. She evaluated several SIEM solutions and chose an open-source option.
She deployed the SIEM and configured use cases for detecting threats. She used AI to generate SIEM rules and set up alert triaging. She created dashboards to visualize security events.
Within a few weeks, the SIEM detected a potential ransomware attack. Amara's quick response prevented the attack from spreading. She learned that SIEM is essential for effective incident detection.
Definition: SIEM (Security Information and Event Management) is a system that collects, analyzes, and correlates logs from various sources to detect threats.
Why it is important: SIEM provides a centralized view of security events, enabling faster detection and response.
π Mini summary: SIEM architecture includes data sources, log collection, normalization, storage, analysis, dashboards, and alerting.
Definition: SIEM solutions are software platforms that provide SIEM capabilities.
π Mini summary: SIEM solutions provide centralized monitoring, correlation, and alerting, but can be complex, costly, and lead to alert fatigue.
Definition: SIEM deployment is the process of implementing a SIEM solution.
π Mini summary: SIEM deployment involves planning, choosing a solution, deploying, integrating, configuring, testing, and monitoring.
Definition: Use case management is the process of defining and managing SIEM use cases.
π Mini summary: Use case management involves defining, configuring, testing, deploying, and monitoring SIEM use cases.
Definition: Incident detection with SIEM involves using SIEM to identify and respond to security incidents.
π Mini summary: Incident detection with SIEM involves collecting logs, normalizing, correlating, alerting, investigating, and responding.
Definition: AI can be used to generate SIEM rules automatically.
π Mini summary: AI can automate SIEM rule generation, improving accuracy and adaptability.
Definition: Alert triaging is the process of prioritizing alerts based on severity.
π Mini summary: Alert triaging prioritizes alerts based on severity, impact, and urgency.
Definition: Correlation identifies patterns across multiple events. Multi-domain event detection analyzes events across different domains.
π Mini summary: Correlation identifies patterns across events. Multi-domain detection analyzes events across network, host, application, and user domains.
Definition: Visualization and dashboards provide a visual representation of security data. SOC reports summarize security events and incidents.
π Mini summary: Visualization, dashboards, and SOC reports provide a visual representation of security data and summarize events.
Definition: Best practices for effective SIEM implementation.
π Mini summary: Best practices for SIEM include collecting logs from all sources, normalizing logs, creating effective rules, fine-tuning, creating dashboards, and continuous monitoring.
Did you know? SIEM can reduce response times by up to 90%.
Did you know? AI can generate SIEM rules automatically.
Did you know? SIEM dashboards provide real-time visibility into security events.
| Feature | Commercial SIEM | Open-Source SIEM |
|---|---|---|
| Cost | High | Low |
| Support | Vendor-provided | Community-driven |
| Features | Advanced | Basic |
| Best for | Large enterprises | Small-to-medium businesses |
| Component | Purpose |
|---|---|
| Log Collection | Gather logs from sources |
| Normalization | Standardize log formats |
| Storage | Store logs for analysis |
| Analysis | Correlate events |
| Dashboards | Visualize security data |
| Alerting | Generate alerts for threats |
Congratulations! You have completed Module Four. You now know:
You are now ready to move on to Module Five, where you will learn about Proactive Threat Detection and Threat Hunting.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. SIEM | A. A specific scenario for detecting threats |
| 2. Normalization | B. Security Information and Event Management |
| 3. Use Case | C. Converting logs into a standard format |
| 4. Dashboard | D. A visual display of security data |
| 5. Alert Triage | E. Prioritizing alerts |
Answers: 1-B, 2-C, 3-A, 4-D, 5-E
In groups of 3-4, deploy a SIEM solution (ELK Stack, Splunk, or Wazuh). Create dashboards and rules to detect threats. Present your setup to the class.
Write a one-page report on a SIEM tool of your choice (ELK Stack, Splunk, or Wazuh). Include its features and use cases.
Project: "SIEM Implementation." Implement a SIEM solution for a fictional organization. Include log collection, use cases, dashboards, and alerts. Present your solution to the class.
Set up a SIEM environment using ELK Stack or Wazuh. Collect logs from at least two sources. Create dashboards and rules to detect threats.
Research the differences between ELK Stack and Splunk. Write a one-page summary of the differences and which is better for specific use cases.
Fill-in-the-Blank Answers:
True or False Answers: 1-T, 2-T, 3-T, 4-F, 5-T, 6-F, 7-T, 8-F, 9-F, 10-T
In Module Five, you will learn about Proactive Threat Detection and Threat Hunting. You will explore threat intelligence, threat hunting methodologies, and tools.
Welcome to Module Five of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore proactive threat detection and threat hunting. You will learn how to stay ahead of attackers by proactively hunting for threats.
Think of threat hunting as cybersecurity detective work. Instead of waiting for alerts, hunters actively search for signs of compromise. By the end of this module, you will be able to conduct threat hunts using various tools and frameworks.
π‘ What you will learn: Threat intelligence fundamentals, types, and strategies, threat intelligence sources and platforms (TIP), threat intelligence-driven SOC operations, threat hunting significance and frameworks, threat hunting with PowerShell, YARA, and hunting tools, structured and unstructured threat hunting, and data transformation techniques.
By the end of this module, you will be able to:
Chuka was a Tier 2 SOC analyst at a bank in Lagos. He noticed that traditional alerting was not catching all threats. He decided to start threat hunting.
He used threat intelligence to guide his hunts. He used PowerShell to search for suspicious activity on endpoints. He used YARA rules to identify malware. His proactive hunting uncovered a persistent threat that had evaded detection.
Chuka's efforts prevented a major data breach. He learned that threat hunting is essential for staying ahead of attackers.
Definition: Threat intelligence is information about threats that helps organizations defend against them.
Why it is important: Threat intelligence provides context about threats, enabling proactive defense.
π Mini summary: Threat intelligence provides information about threats, enabling proactive defense.
Definition: Threat intelligence can be categorized into different types.
π Mini summary: Threat intelligence types include strategic, tactical, operational, and technical.
Definition: Threat intelligence sources are places where threat intelligence is obtained.
π Mini summary: Threat intelligence sources include OSINT, commercial intelligence, information sharing, and government sources.
Definition: A Threat Intelligence Platform (TIP) is a tool that collects, analyzes, and shares threat intelligence.
π Mini summary: Threat Intelligence Platforms collect, analyze, and share threat intelligence.
Definition: Threat intelligence-driven SOC operations use intelligence to guide detection and response.
π Mini summary: Threat intelligence-driven SOC operations use intelligence to guide detection and response.
Definition: Threat hunting is the proactive search for threats that have evaded detection.
Why it is important: Threat hunting helps organizations find and eliminate threats before they cause damage.
π Mini summary: Threat hunting is the proactive search for threats, enabling early detection and improved response.
Definition: Threat hunting frameworks provide structured approaches to hunting.
π Mini summary: Threat hunting frameworks include MITRE ATT&CK, Cyber Kill Chain, and the Diamond Model.
Definition: PowerShell is a powerful tool for threat hunting on Windows systems.
π Mini summary: PowerShell is a powerful tool for threat hunting on Windows systems.
Definition: YARA is a tool for identifying malware based on patterns in files or processes.
π Mini summary: YARA is a tool for identifying malware based on patterns in files or processes.
Definition: Threat hunting can be structured or unstructured.
π Mini summary: Structured threat hunting follows a defined methodology, while unstructured hunting is ad-hoc.
Definition: Data transformation techniques convert data into a format suitable for analysis.
π Mini summary: Data transformation techniques include normalization, enrichment, aggregation, and filtering.
Definition: Best practices for effective threat hunting.
π Mini summary: Best practices for threat hunting include using threat intelligence, using frameworks, collaborating, documenting findings, and continuously improving.
Did you know? Threat hunting can detect threats that have been active for months.
Did you know? MITRE ATT&CK is updated regularly with new techniques.
Did you know? YARA is used by many antivirus companies.
| Type | Description | Audience |
|---|---|---|
| Strategic | High-level insights | Decision-makers |
| Tactical | TTPs | Analysts |
| Operational | Specific threat information | Operators |
| Technical | IoCs | Technical staff |
| Feature | Structured | Unstructured |
|---|---|---|
| Methodology | Defined | Ad-hoc |
| Consistency | High | Low |
| Best for | Large organizations | Small teams |
Congratulations! You have completed Module Five. You now know:
You are now ready to move on to Module Six, where you will learn about Incident Response and Investigation.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. Threat Intelligence | A. Proactive search for threats |
| 2. Threat Hunting | B. Information about threats |
| 3. MITRE ATT&CK | C. Tool for identifying malware |
| 4. YARA | D. Knowledge base of adversary tactics and techniques |
| 5. TIP | E. Threat Intelligence Platform |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
In groups of 3-4, conduct a mock threat hunt. Develop a hypothesis, gather data, and analyze it. Present your findings to the class.
Write a one-page report on a threat hunting case study. Include the hypothesis, methodology, findings, and lessons learned.
Project: "Threat Hunting Plan." Create a threat hunting plan for a fictional organization. Include objectives, methodologies, data sources, and tools. Present your plan to the class.
Create a threat hunting plan for a specific threat (e.g., ransomware). Include the hypothesis, data sources, and steps to investigate.
Research a real-world threat hunting case study. Write a one-page summary of the case study and what was learned.
Fill-in-the-Blank Answers:
True or False Answers: 1-F, 2-T, 3-T, 4-F, 5-T, 6-F, 7-T, 8-F, 9-F, 10-T
In Module Six, you will learn about Incident Response and Investigation. You will explore incident response processes, playbooks, and tools.
Welcome to Module Six of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore incident response and investigation. You will learn how to respond to incidents, investigate root causes, and recover from attacks.
Think of incident response as the emergency plan for cyber attacks. By the end of this module, you will be able to lead incident response efforts and conduct thorough investigations.
π‘ What you will learn: Incident response process and phases, responding to network, application, email, and insider incidents, malware incident response, SOC playbooks in incident response, enhanced response with EDR/XDR, and case creation and professional reporting.
By the end of this module, you will be able to:
Kemi was a Tier 2 SOC analyst at a bank in Lagos. One morning, she received an alert about a potential ransomware attack. She activated the incident response plan.
She identified the affected systems and isolated them to prevent the spread. She eradicated the malware and recovered data from backups. After the incident, she created a case and wrote a detailed report.
Kemi's quick actions prevented a major breach. She learned that a well-prepared incident response plan is essential for minimizing damage.
Definition: Incident response is the process of preparing for, detecting, containing, eradicating, recovering from, and learning from security incidents.
Why it is important: Incident response minimizes the impact of security incidents and helps organizations recover quickly.
π Mini summary: Incident response is the process of preparing for, detecting, and responding to security incidents.
Definition: The incident response process consists of six phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
Plan, train, and equip the team.
Detect and confirm the incident.
Stop the incident from spreading.
Remove the threat.
Restore normal operations.
Learn and improve.
π Mini summary: The IR process includes Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
Definition: Network incidents involve attacks on network infrastructure.
π Mini summary: Responding to network incidents involves identifying, containing, eradicating, recovering, and learning.
Definition: Application incidents involve attacks on software applications.
π Mini summary: Responding to application incidents involves identifying, containing, eradicating, recovering, and learning.
Definition: Email incidents involve attacks delivered via email.
π Mini summary: Responding to email incidents involves identifying, containing, eradicating, recovering, and learning.
Definition: Insider incidents involve attacks from within the organization.
π Mini summary: Responding to insider incidents involves identifying, containing, eradicating, recovering, and learning.
Definition: Malware incident response involves responding to malware infections.
π Mini summary: Malware incident response involves identifying, containing, eradicating, recovering, and learning.
Definition: SOC playbooks are step-by-step guides for responding to incidents.
π Mini summary: SOC playbooks provide step-by-step guidance for responding to incidents.
Definition: EDR (Endpoint Detection and Response) and XDR (Extended Detection and Response) are tools that enhance incident response.
π Mini summary: EDR and XDR enhance incident response by providing detection and response capabilities.
Definition: Case creation involves documenting the incident. Professional reporting communicates the findings.
π Mini summary: Case creation documents the incident. Professional reporting communicates the findings.
Did you know? The average time to detect a breach is over 200 days.
Did you know? EDR tools can isolate compromised endpoints automatically.
Did you know? XDR provides unified detection and response across domains.
| Type | Description | Response Approach |
|---|---|---|
| Network | Attacks on infrastructure | Isolate network segments |
| Application | Attacks on software | Isolate application |
| Attacks via email | Isolate email accounts | |
| Insider | Attacks from within | Restrict access |
| Malware | Malware infections | Isolate infected systems |
| Feature | EDR | XDR |
|---|---|---|
| Focus | Endpoints | Multiple domains |
| Detection | Endpoint threats | Cross-domain threats |
| Response | Endpoint response | Unified response |
Congratulations! You have completed Module Six. You now know:
You are now ready to move on to Module Seven, where you will learn about Forensics Investigation and Malware Analysis.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. Incident Response | A. Step-by-step guide for response |
| 2. Playbook | B. The process of preparing for, detecting, and responding to incidents |
| 3. EDR | C. Extended Detection and Response |
| 4. XDR | D. Endpoint Detection and Response |
| 5. Case Creation | E. Documenting the incident |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
In groups of 3-4, create an incident response playbook for a specific type of incident (e.g., ransomware, phishing). Present your playbook to the class.
Write a one-page report on a real-world security incident. Include the incident type, response, and lessons learned.
Project: "Incident Response Plan." Create an incident response plan for a fictional organization. Include the IR process, playbooks, communication plan, and lessons learned process. Present your plan to the class.
Create an incident response playbook for a specific type of incident (e.g., ransomware). Include step-by-step instructions, roles, and communication guidelines.
Research a real-world security incident. Write a one-page report on how the incident was handled and what could have been done better.
Fill-in-the-Blank Answers:
True or False Answers: 1-T, 2-F, 3-T, 4-T, 5-F, 6-T, 7-T, 8-F, 9-T, 10-F
In Module Seven, you will learn about Forensics Investigation and Malware Analysis. You will explore forensic techniques and malware analysis tools.
Welcome to Module Seven of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore forensics investigation and malware analysis. You will learn how to investigate incidents, analyze malware, and recover evidence.
Think of forensics as cybersecurity detective work. By the end of this module, you will be able to conduct forensic investigations and analyze malware.
π‘ What you will learn: Forensic investigation fundamentals, investigating network, application, email, and insider incidents, malware analysis (static and dynamic), memory analysis with Volatility, triage artifact collection with KAPE, and incident response with Velociraptor.
By the end of this module, you will be able to:
Ngozi was a Tier 2 SOC analyst at a bank in Lagos. She received an alert about a potential malware infection. She started a forensic investigation.
She used Volatility to analyze memory dumps and identify malicious processes. She used KAPE to collect triage artifacts. She used Velociraptor to investigate endpoints. Her investigation revealed a new malware variant.
Ngozi's forensic skills helped the team contain the incident. She learned that forensics is essential for incident response.
Definition: Forensic investigation is the process of collecting, preserving, and analyzing digital evidence.
Why it is important: Forensics helps organizations understand what happened and gather evidence for legal proceedings.
π Mini summary: Forensic investigation is the process of collecting, preserving, and analyzing digital evidence.
Definition: Network forensics involves analyzing network traffic to identify malicious activity.
π Mini summary: Network forensics involves capturing and analyzing network packets to identify malicious activity.
Definition: Application forensics involves analyzing application logs and data to identify malicious activity.
π Mini summary: Application forensics involves analyzing application logs to identify malicious activity.
Definition: Email forensics involves analyzing email traffic and content to identify malicious activity.
π Mini summary: Email forensics involves analyzing email traffic and content to identify malicious activity.
Definition: Insider forensics involves investigating malicious activity from within the organization.
π Mini summary: Insider forensics involves investigating malicious activity from within the organization.
Definition: Static analysis involves examining malware without executing it.
π Mini summary: Static analysis examines malware without executing it, using file properties, strings, and code analysis.
Definition: Dynamic analysis involves executing malware in a sandbox to observe its behavior.
π Mini summary: Dynamic analysis executes malware in a sandbox to observe its behavior.
Definition: Volatility is a framework for analyzing memory dumps.
π Mini summary: Volatility is a framework for analyzing memory dumps, with commands like pslist, netscan, and cmdline.
Definition: KAPE (Kroll Artifact Parser and Extractor) is a tool for collecting and parsing forensic artifacts.
π Mini summary: KAPE is a tool for collecting and parsing forensic artifacts, useful for incident response.
Definition: Velociraptor is a tool for incident response and digital forensics.
π Mini summary: Velociraptor is a tool for incident response and digital forensics.
Did you know? Volatility can analyze memory dumps from Windows, Linux, and Mac.
Did you know? KAPE can collect artifacts from live systems.
Did you know? Velociraptor is used by many SOCs.
| Feature | Static | Dynamic |
|---|---|---|
| Execution | No | Yes |
| Risk | Low | Medium |
| Insight | Code structure | Behavior |
| Best for | Initial analysis | Detailed analysis |
| Tool | Purpose | Best for |
|---|---|---|
| Volatility | Memory analysis | Memory dumps |
| KAPE | Artifact collection | Triage |
| Velociraptor | Incident response | Forensics and response |
Congratulations! You have completed Module Seven. You now know:
You are now ready to move on to Module Eight, where you will learn about SOC for Cloud Environments.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. Static Analysis | A. Executes malware in a sandbox |
| 2. Dynamic Analysis | B. Examines malware without execution |
| 3. Volatility | C. Memory forensics framework |
| 4. KAPE | D. Collects and parses artifacts |
| 5. Velociraptor | E. Incident response and forensics |
Answers: 1-B, 2-A, 3-C, 4-D, 5-E
In groups of 3-4, analyze a sample malware file. Use static and dynamic analysis techniques. Present your findings to the class.
Write a one-page report on a forensic tool of your choice (Volatility, KAPE, or Velociraptor). Include its features and use cases.
Project: "Forensics Investigation." Conduct a forensic investigation for a fictional incident. Use Volatility, KAPE, and Velociraptor. Present your findings to the class.
Analyze a memory dump using Volatility. Identify malicious processes, network connections, and command history. Write a report on your findings.
Research a real-world forensic case study. Write a one-page summary of the case study and what was learned.
Fill-in-the-Blank Answers:
True or False Answers: 1-T, 2-F, 3-T, 4-T, 5-F, 6-T, 7-T, 8-T, 9-F, 10-T
In Module Eight, you will learn about SOC for Cloud Environments. You will explore Azure SOC, AWS SOC, and GCP SOC.
Welcome to Module Eight of your Certified Security Operations Centre Analyst Level 2 course! In this module, we will explore SOC for cloud environments. You will learn how to extend SOC capabilities to the cloud.
Think of this module as taking the SOC to the cloud. By the end of this module, you will understand how to secure cloud environments using SOC principles and tools.
π‘ What you will learn: Introduction to Cloud SOC, Azure SOC Architecture and Microsoft Sentinel, AWS SOC Architecture and AWS Security Hub, Google Cloud Platform (GCP) SOC and Security Command Center, and cloud-native security tools and integration.
By the end of this module, you will be able to:
Chidi was a Tier 2 SOC analyst at a bank in Lagos. The bank was migrating to the cloud, and Chidi needed to extend the SOC to the cloud.
He designed an Azure SOC architecture using Microsoft Sentinel. He used AWS Security Hub for AWS workloads. He used GCP Security Command Center for Google Cloud. He integrated cloud-native security tools to monitor threats.
Chidi's cloud SOC helped the bank detect and respond to cloud-based threats. He learned that cloud security is essential for modern organizations.
Definition: A Cloud SOC extends traditional SOC capabilities to cloud environments.
Why it is important: As organizations migrate to the cloud, they need to monitor and protect cloud resources.
π Mini summary: A Cloud SOC extends traditional SOC capabilities to cloud environments.
Definition: Azure SOC architecture uses Microsoft Sentinel to monitor and protect Azure workloads.
π Mini summary: Azure SOC architecture uses Microsoft Sentinel, Azure Monitor, Azure Security Center, and Azure Log Analytics.
Definition: Microsoft Sentinel is a cloud-native SIEM for Azure.
π Mini summary: Microsoft Sentinel is a cloud-native SIEM for Azure with data collection, detection, investigation, and response capabilities.
Definition: AWS SOC architecture uses AWS Security Hub to monitor and protect AWS workloads.
π Mini summary: AWS SOC architecture uses AWS Security Hub, GuardDuty, AWS Config, and AWS CloudTrail.
Definition: AWS Security Hub is a centralized security management service for AWS.
π Mini summary: AWS Security Hub provides a centralized view of security alerts, compliance checks, and integrations.
Definition: GCP SOC architecture uses Google Cloud Security Command Center to monitor and protect GCP workloads.
π Mini summary: GCP SOC architecture uses Security Command Center, Cloud Audit Logs, Cloud Monitoring, and Cloud Armor.
Definition: Security Command Center is a centralized security management service for GCP.
π Mini summary: Security Command Center provides a centralized view of security alerts, compliance checks, and integrations for GCP.
Definition: Cloud-native security tools are built specifically for cloud environments.
π Mini summary: Cloud-native security tools are built specifically for cloud environments and include Azure Sentinel, AWS Security Hub, and GCP Security Command Center.
Definition: Integration connects cloud-native security tools with existing SOC tools.
π Mini summary: Integration connects cloud-native security tools with existing SOC tools for enhanced detection and response.
Definition: Best practices for effective Cloud SOC operations.
π Mini summary: Best practices for Cloud SOC include using cloud-native tools, integrating with existing SOC, continuous monitoring, automation, and staying updated.
Did you know? Azure Sentinel uses AI for threat detection.
Did you know? AWS Security Hub integrates with over 50 AWS services.
Did you know? GCP Security Command Center provides continuous monitoring.
| Feature | Azure | AWS | GCP |
|---|---|---|---|
| SIEM | Microsoft Sentinel | AWS Security Hub | Security Command Center |
| Monitoring | Azure Monitor | AWS Config | Cloud Monitoring |
| Logging | Azure Log Analytics | AWS CloudTrail | Cloud Audit Logs |
| Threat Detection | Sentinel AI | GuardDuty | Security Command Center |
| Tool | Purpose | Best for |
|---|---|---|
| Azure Sentinel | SIEM | Azure workloads |
| AWS Security Hub | Security management | AWS workloads |
| GCP Security Command Center | Security management | GCP workloads |
Congratulations! You have completed Module Eight. You now know:
You have now completed all eight modules of the Certified SOC Analyst Level 2 course. You are ready to work as a Tier 2 SOC Analyst.
Match the term on the left with its description on the right.
| Term | Description |
|---|---|
| 1. Cloud SOC | A. Centralized security management for AWS |
| 2. Azure Sentinel | B. Cloud-native SIEM for Azure |
| 3. AWS Security Hub | C. Centralized security management for GCP |
| 4. GCP Security Command Center | D. A SOC that monitors cloud environments |
| 5. Integration | E. Connecting cloud-native tools with existing SOC |
Answers: 1-D, 2-B, 3-A, 4-C, 5-E
In groups of 3-4, design a Cloud SOC architecture for a fictional organization. Choose a cloud provider (Azure, AWS, or GCP). Present your architecture to the class.
Write a one-page report on a cloud-native security tool (Azure Sentinel, AWS Security Hub, or GCP Security Command Center). Include its features and use cases.
Project: "Cloud SOC Architecture." Design a Cloud SOC architecture for a fictional organization. Choose a cloud provider and include the key components. Present your architecture to the class.
Design a Cloud SOC architecture for a fictional organization. Choose a cloud provider and document the key components and tools.
Research a real-world Cloud SOC implementation. Write a one-page summary of the case study and what was learned.
Fill-in-the-Blank Answers:
True or False Answers: 1-T, 2-F, 3-T, 4-F, 5-T, 6-F, 7-T, 8-T, 9-F, 10-T
You have now completed all eight modules of the Certified SOC Analyst Level 2 course. You are ready to work as a Tier 2 SOC Analyst. Keep learning, stay curious, and continue to improve your skills.