Glusvox
Cyber Security

Become A Job-Ready
SOC & Incident Response Analyst

A 26-module Blue Team program covering SIEM engineering, incident handling, digital forensics, and threat hunting.

SOC Analyst & Incident Response Specialist (L1/L2 Blue Team)

Learn to detect, investigate, and respond to real attacks - SIEM engineering with Splunk and the Elastic Stack, memory and disk forensics, threat hunting, and ransomware triage, capped with a live SOC shift simulation.

  • 26 Hands-On Lab Modules
  • Splunk & Elastic Stack (ELK) SIEM Labs
  • Memory & Disk Forensics Practice
  • 4-Week Live SOC Shift Internship

Full Course Curriculum

26 modules, from SOC operations to a guided live SOC shift internship.

Module 1: SOC Operations & Governance
  • Tiered SOC structure (L1 Triage, L2 Incident Responder, L3 Threat Hunter), SLA management, ticketing, and shift handovers.
Module 2: Threat Actor Profiles & Cyber Kill Chain
  • APT groups, cybercrime syndicates, initial access to exfiltration stages, and Lockheed Martin Kill Chain mapping.
Module 3: The MITRE ATT&CK Framework
  • Tactics, Techniques, and Procedures (TTPs), matrix navigation, mapping detections, and sub-technique identification.
Module 4: Windows Event Log Architecture
  • Security log mechanics, critical event IDs (Logon types, process creation 4688, user creation, privilege assignment).
Module 5: Sysmon Deployment & Advanced Logging
  • System Monitor configuration, process creation, network connections, process injection, and file creation tracking.
Module 6: Linux System Auditing & Log Analysis
  • Syslog mechanics, /var/log analysis, auditd rules, systemd journal logging, and detecting privilege escalation traces.
Module 7: SIEM Architecture Fundamentals
  • Data collection agents, forwarders, indexers, search heads, data normalization, and retention policies.
Module 8: Splunk Administration & Querying (SPL)
  • Search Processing Language fundamentals, pipeline operations, sub-searches, stats, timecharts, and lookup tables.
Module 9: Open-Source SIEM: Wazuh & Elastic Stack (ELK)
  • Wazuh agent deployment, decoder/rule customization, Elasticsearch indexing, Logstash pipelines, and Kibana dashboard building.
Module 10: Detection Engineering with Sigma Rules
  • Sigma syntax, translating generic detection rules to Splunk SPL and Elastic KQL, and testing detection logic.
Module 11: Network Traffic Analysis with Wireshark & Tshark
  • Packet carving, protocol hierarchy analysis, tracking TCP streams, and decrypting TLS with pre-master keys.
Module 12: Network Intrusion Analysis: Snort, Zeek & Suricata
  • Analyzing Zeek metadata logs (conn.log, dns.log, http.log), alert correlation, and custom signature deployment.
Module 13: Identifying Network-Based Attacks
  • Spotting port scans, DNS exfiltration/tunneling, C2 beaconing rhythms, and brute-force patterns in raw traffic.
Module 14: Cyber Threat Intelligence (CTI) & Indicator Lifecycle
  • Indicators of Compromise (IoCs) vs. Indicators of Attack (IoAs), STIX/TAXII standards, and MISP platform usage.
Module 15: Incident Handling Methodology: NIST SP 800-61
  • Preparation, detection & analysis, containment, eradication, recovery, and post-incident activities.
Module 16: Endpoint Detection & Response (EDR) Operations
  • EDR agent telemetry, alert triage, host isolation, live process termination, and memory dump initiation.
Module 17: Memory Forensics with Volatility 3
  • Analyzing RAM dumps, running processes (pslist, pstree), finding injected code (malfind), and extracting network artifacts.
Module 18: Windows Disk Forensics Artifacts
  • Master File Table (MFT), Prefetch files, Shimcache, Amcache, and Shellbags for proof of program execution.
Module 19: Browser & Email Forensics
  • Mail header analysis (SPF, DKIM, DMARC), phishing link analysis, browser history SQLite parsing, and download artifact recovery.
Module 20: Yara Rule Development for Malware Detection
  • Writing string, hex, and regex rules; conditioning; compiling; and scanning systems/files for malicious binaries.
Module 21: Threat Hunting Methodologies
  • Hypothesis-driven hunting, baselining normal behaviors, outlier analysis, and frequency analysis (least-frequency of occurrence).
Module 22: Ransomware Attack Triage & Containment
  • Identifying ransomware execution chains (vssadmin shadow copy deletion, encryption phases), host containment, and recovery protocol.
Module 23: SOAR Platforms & Playbook Automation
  • Security Orchestration, Automation, and Response basics; automated IP enrichment; user suspension; and firewall blocking playbooks.
Module 24: Cloud Incident Detection (AWS / Azure Basics)
  • CloudTrail log parsing, Azure Sentinel fundamentals, impossible travel alerts, and unauthorized IAM role assumptions.
Module 25: Incident Response Documentation & Root Cause Analysis
  • Building incident timelines, drafting executive summaries, root cause analysis (RCA), and evidence chain of custody.
Module 26: Capstone Project & Live SOC Shift Internship
  • Project: End-to-end investigation of an APT breach scenario across Windows/Linux hosts - analyze SIEM alerts, reconstruct the attack timeline, extract IoCs, and produce an Incident Response Report.
  • Internship: 4-week live SOC shift simulation - triaging alert queues, filtering false positives within SLAs, and coordinating response steps with remediation playbooks.

Training Built, To Get You Hired

We don't just teach concepts we build job-ready security professionals through hands-on labs, certified mentors, and real career support.

Hands-On Labs

Every module is practiced in real lab environments, not just slides and theory.

Industry Mentors

Learn from CEH and CISSP-certified practitioners who work in security every day.

Certification-Aligned

Curriculum mapped directly to CEH, CISSP, and other industry-recognized exams.

Career Support

Resume, interview prep, and job placement support through our in-house career team.

0
Students Trained
0
Certification Pass Rate
0
Expert Mentors

Our Proven Training Journey

A structured 4 step path from beginner to certified, job-ready security professional.

01

Foundations & Assessment

We assess your starting point and build core security fundamentals before diving into labs.

02

Hands-On Lab Training

Guided, real-world labs across networking, web, mobile, and cloud security.

03

Certification Prep

Structured exam prep and mock tests aligned to CEH, CISSP, and other certifications.

04

Career Support & Placement

Resume building, interview prep, and job placement support for your first security role.

Let's Build Your Security Career

Book a free counselling call with our training team. No sales pitch just a clear path to your first cyber security role.

Contact Info
Email
support@glusvox.com
Address
30 N Gould St Ste N, Sheridan, WY 82801
Hours
Monโ€“Fri, 9:00 AM โ€“ 6:00 PM
Follow Us