Program overview
This program trains SOC analysts on the daily work of a security operations center: reviewing alerts, building an investigation, deciding when to escalate, and writing up what happened. Exercises run in an isolated lab set up with the log sources, detection rules, and ticketing steps your team uses.
It suits tier 1 and tier 2 analysts, new hires joining an existing SOC, and analysts moving into threat hunting or detection work. Shift leads and SOC managers can join the debriefs to see where handoffs and escalation paths need work. DeployOpen engineers facilitate every session.
Skills covered
Alert triage
Sorting alerts by severity and context, closing benign activity with a clear reason, and picking out the events that need investigation.
Investigation and timelines
Pivoting across endpoint, network, identity, and cloud logs to reconstruct a sequence of events and identify the affected hosts and accounts.
Escalation and handoff
Deciding when an alert becomes an incident, what an escalation should contain, and how to hand a case to incident response or the next shift.
Threat hunting basics
Forming a hypothesis from a known technique, writing queries to test it, and turning a useful hunt into a detection rule.
AI-assisted attacks and AI tool alerts
Investigating phishing and malware campaigns produced with AI tools, and triaging alerts and summaries from AI features in your security tooling by checking them against the raw evidence.
Case documentation
Writing case notes that state what is known, what is not yet proven, and what evidence is still needed, so another analyst can pick up the case.
How the program runs
We review your team's roles, common alert types, log sources, and escalation procedures. Short practical tasks or interviews show where analysts are confident and where they need practice. We agree learning objectives with the SOC manager.
We build scenarios around your detection stack, using synthetic data in the log formats your tools produce. Each scenario has a written objective, the evidence analysts should find, and the decisions they need to make. Your team confirms the scope before any session.
Analysts work through the scenarios in the isolated lab, individually or as a shift. A DeployOpen engineer facilitates, releases new information as the scenario develops, and records the decisions and evidence each analyst uses.
After each exercise we walk through the timeline with the group, compare what analysts found with what the scenario contained, and note gaps in skills, procedures, detection rules, and log coverage.
Formats
| Format | Who it suits | What it covers |
|---|---|---|
| Hands-on lab exercise | Analyst teams who want practice on a specific skill or alert type | One or more investigation scenarios in the isolated lab, followed by a debrief |
| Multi-day program | New analysts, a growing SOC, or a team adopting a new toolset | A sequence of modules from triage through investigation, hunting, and escalation, with a debrief after each exercise |
| Tabletop session | Shift leads, SOC managers, and incident response contacts | Escalation decisions, handoffs between shifts and teams, and communication during a major incident |
| Recurring drills | Established SOCs keeping skills current | New scenarios based on recently reported techniques or changes to your environment, run at an agreed interval |
Sample modules
Phishing to account compromise
An AI-written phishing email leads to stolen credentials and a suspicious sign-in. Analysts trace the message, the sign-in, and any mailbox rule changes.
Ransomware precursor activity
Discovery commands, credential dumping, and lateral movement appear in endpoint logs before encryption starts. Analysts identify the earliest useful signal.
Cloud identity misuse
A cloud access key is used from an unexpected location to list storage and create a new user. Analysts work from cloud audit logs.
Insider data movement
A user copies a large volume of files to a personal storage service. Analysts decide whether it is a policy breach, an error, or theft, and who to involve.
Alert from an AI security assistant
An AI feature in the security tooling flags an incident and writes a summary. Analysts check the summary against the logs and note what it missed or overstated.
Mixed alert queue
A queue of true and false positives. Analysts prioritize, close benign alerts with clear reasons, and escalate the cases that need it.
What you receive
Each engagement ends with written material your team can use after the sessions finish.
Debrief notes
- Timeline of each scenario and the decisions analysts made
- Evidence analysts found and evidence they missed
- Points where escalation or handoff slowed down
Detection and log findings
- Alerts that fired, did not fire, or fired without enough context
- Log sources that were missing or hard to query
- Suggested detection rule changes mapped to MITRE ATT&CK techniques
Runbook and process improvements
- Recommended edits to triage and escalation runbooks
- Gaps in case documentation templates
- Ownership questions to settle between the SOC and other teams
Materials to rerun
- Scenario briefs and facilitator notes
- Synthetic datasets used in the lab
- Expected findings so your team can run each exercise again
Common questions
Who should attend?
Tier 1 to tier 3 analysts, threat hunters, and detection engineers. SOC managers and shift leads can join the debriefs and tabletop sessions.
Do the exercises use our tools?
Scenarios are tailored to your environment and tools. We match the log formats, detection rules, and ticketing steps your analysts use, inside an isolated lab.
Is it remote or on-site?
Remote or on-site delivery can be agreed for each part of the program.
How do you measure progress?
Each exercise has written objectives and expected findings. The debrief records which objectives each group met. Running a similar scenario later shows whether the gaps have closed.
Can the program be repeated?
Yes. Scenario materials are handed over so your team can rerun them, and we can build new scenarios as your tools and the threats you face change.
How is our information protected?
Exercises use synthetic data in an isolated lab. We sign an NDA on request, and each engagement has a fixed, agreed scope.
How to prepare
Share a short description of your SOC: tiers and roles, main tools, log sources, and escalation path. A few alert types or past incidents that caused difficulty help us choose scenarios.
Name a contact who can confirm scope and answer questions during scenario design. Let analysts know the sessions are for practice and that the debrief looks at process and tooling as well as individual decisions.
Framework mapping
Scenarios and findings are described with MITRE ATT&CK techniques, so detection gaps can be compared with your existing coverage. Recommended defensive changes can reference MITRE D3FEND.
Learning objectives can be mapped to work roles in the NICE Framework, such as Defensive Cybersecurity, Incident Response, and Threat Analysis, to support role definitions and training plans.

