دوره TCM Security – Security Operations (SOC) 201

Security Operations (SOC) 201 is an intermediate security operations course designed to enhance your skills in detecting, investigating, and responding to complex cyber threats at scale. After establishing fundamental security operations knowledge and practical skills in SOC 101, the next logical step is to progress your career by applying advanced investigation methodologies and grasping the responsibilities of an Incident Responder and Threat Hunter. The SOC 201 curriculum teaches analysts how to identify, hunt, and respond to real-world adversary tactics and techniques. With a practical, hands-on focus, the curriculum provides realistic scenarios where students investigate sophisticated threats across multiple systems, learning to detect and respond effectively in enterprise-scale environments. The course also integrates proactive threat hunting as part of a continuous detection and response cycle, giving analysts the mental models to identify active threats, uncover gaps, and feed insights back into investigative processes to improve future detection and response efforts.

Syllabus

  1. Introduction
  2. Lab Setup
  3. Introduction to Incident Response
  4. Introduction to Threat Hunting
  5. Data Transformation
  6. Understanding Anomalies
  7. Dissecting Threat Reports
  8. Threat Hunting Lab
  9. Collection at Scale
  10. PowerShell 101
  11. PowerShell for Incident Response
  12. Conclusion

TCM Security – Security Operations (SOC) 201