Classes Security

TCM Security

SOC Level 1

  • 4 days
  • 2 upcoming dates
  • 2 guaranteed to run
  • May qualify for CEU/PDU credit

Upcoming dates

All times shown in the class's own timezone. 2 of 2 are guaranteed to run, meaning they go ahead regardless of enrollment.

Dates Starts Where Status Seat Book
Aug 17-20 9:00 AM to 5:00 PM EDT Live virtual GUARANTEED $1,999
Nov 2-5 8:00 AM to 4:00 PM EST Live virtual GUARANTEED $1,999

About this class

Take your SOC analyst skills to the next level with four full days of intensive live training, labs, and challenges designed to build the foundational skills essential for success in defensive security operations. This course provides deep, practical coverage of monitoring, detection, analysis, and incident response across key areas including phishing, network security, endpoint protection, SIEM management, threat intelligence, and DFIR (Digital Forensics and Incident Response).

By the end of the training, you’ll have a comprehensive understanding of Security Operations Center functions and investigative techniques, developed through real-world scenarios that reflect the demands placed on today’s SOC professionals.

This course includes an Exam Vouchers for TCM Security’s Practical SOC Analyst Associate (PSAA) certification. Each exam voucher includes 1 exam attempt and is valid for 12-months from the course completion date.

What you'll be able to do

  • Security Operations Fundamentals
  • Phishing Analysis
  • Network Security Monitoring
  • Network Traffic Analysis
  • Endpoint Security Monitoring
  • Endpoint Detection and Response
  • Log Analysis and Management
  • Security Information and Event Management (SIEM)
  • Threat Intelligence
  • Digital Forensics
  • Incident Response

Course outline

Day 1

  • Class Introduction
  • Lab Access, Setup, and Configuration
  • Understanding the SOC
  • Understanding Phishing Attacks and Techniques
  • Email Analysis
  • URL Analysis
  • Attachment Analysis
  • MalDoc Analysis
  • Phishing Defenses
  • Ticket Challenge, Walkthrough and Break
  • Understanding Packets and Flows
  • Network Traffic Analysis with TCPDump
  • Network Traffic Analysis with Wireshark
  • Ticket Challenge

Day 2

  • Understanding Endpoint Security
  • Windows, Hunting Malicious Network Connections
  • Windows, Hunting Malicious Processes
  • Live IR with SysInternals and Autoruns
  • Windows, Understanding Core Processes
  • Windows, Hunting Persistence
  • Ticket Challenge, Walkthrough and Break
  • Linux, Hunting Malicious Network Connections
  • Linux, Hunting Malicious Processes
  • Linux, Understanding Core Processes
  • Linux, Hunting Persistence
  • Ticket Challenge, Walkthrough and Break
  • Understanding the SIEM
  • Common Attack Signatures
  • Command Line Log Analysis
  • Ticket Challenge

Day 3

  • Splunk Introduction
  • Search Processing Language
  • Search Commands
  • Reporting, Alerting, and Dashboards
  • Investigating Intrusions with Splunk
  • Deploying Forwarders
  • Ticket Challenge, Walkthrough and Break
  • Understanding Threat Intelligence
  • Threat Intelligence Frameworks
  • MITRE ATT&CK
  • Ticket Challenge, Walkthrough and Break
  • Detecting Malware with YARA
  • Reading and Writing YARA Rules
  • Ticket Challenge

Day 4

  • Understanding Digital Forensics Investigations
  • Disk Image Acquisition with FTK Imager
  • Memory Acquisition with FTK Imager
  • Ticket Challenge, Walkthrough and Break
  • Windows Forensic Artifacts
  • Forensic Image Analysis with Autopsy
  • Memory Analysis with Volatility
  • Ticket Challenge, Walkthrough and Break
  • The Incident Response Process
  • Training Wrap-Up

Before you attend

System Requirements

  • 8GB RAM & 256GB HDD
  • Up-to-Date OS & Internet Browser
  • Stable Internet connection

Completion of the Practical Help Desk course, A+/Net+ equivalent, or familiarity with the topics such as:

  • Basic familiarity with Windows and Linux operating system components.
  • Experience working with the command-line and knowledge of basic commands and navigation (e.g., cd, ls, cat).
  • Knowledge of network concepts such as subnets, internal vs. external IP addresses, network address translation, and routing.
  • Understanding of foundational security concepts such as the CIA triad, security controls, encryption, and hashing.

Who this is for

Aspiring SOC Analysts and Incident Responders. Individuals with a strong interest in blue teaming and a desire to understand how security operations work in real-world environments. IT professionals with some experience in networking or systems administration who want to expand their skills into the SOC and cybersecurity field. Students looking to prepare for the Practical SOC Analyst Associate (PSAA) exam.

How reserving works. Your card is authorized, not charged. We confirm the seat with the training center, usually within one business day, and take payment only once it is held. If the class turns out to be full we release the authorization and you are not charged.

Request a quote

Tell us how many people and roughly when. We'll come back with dates, seat price, and a total by the end of the next business day.

Class SOC Level 1

No obligation, and we don't add you to a mailing list.