SOC analyst training

Hands-on training for SOC analysts in alert triage, investigation, escalation, and case documentation, built around your team's tools and run in an isolated lab.

On this page

Program overview

This program trains SOC analysts on the daily work of a security operations center: reviewing alerts, building an investigation, deciding when to escalate, and writing up what happened. Exercises run in an isolated lab set up with the log sources, detection rules, and ticketing steps your team uses.

It suits tier 1 and tier 2 analysts, new hires joining an existing SOC, and analysts moving into threat hunting or detection work. Shift leads and SOC managers can join the debriefs to see where handoffs and escalation paths need work. DeployOpen engineers facilitate every session.

Skills covered

Alert triage

Sorting alerts by severity and context, closing benign activity with a clear reason, and picking out the events that need investigation.

Investigation and timelines

Pivoting across endpoint, network, identity, and cloud logs to reconstruct a sequence of events and identify the affected hosts and accounts.

Escalation and handoff

Deciding when an alert becomes an incident, what an escalation should contain, and how to hand a case to incident response or the next shift.

Threat hunting basics

Forming a hypothesis from a known technique, writing queries to test it, and turning a useful hunt into a detection rule.

AI-assisted attacks and AI tool alerts

Investigating phishing and malware campaigns produced with AI tools, and triaging alerts and summaries from AI features in your security tooling by checking them against the raw evidence.

Case documentation

Writing case notes that state what is known, what is not yet proven, and what evidence is still needed, so another analyst can pick up the case.

How the program runs

We review your team's roles, common alert types, log sources, and escalation procedures. Short practical tasks or interviews show where analysts are confident and where they need practice. We agree learning objectives with the SOC manager.

Formats

FormatWho it suitsWhat it covers
Hands-on lab exerciseAnalyst teams who want practice on a specific skill or alert typeOne or more investigation scenarios in the isolated lab, followed by a debrief
Multi-day programNew analysts, a growing SOC, or a team adopting a new toolsetA sequence of modules from triage through investigation, hunting, and escalation, with a debrief after each exercise
Tabletop sessionShift leads, SOC managers, and incident response contactsEscalation decisions, handoffs between shifts and teams, and communication during a major incident
Recurring drillsEstablished SOCs keeping skills currentNew scenarios based on recently reported techniques or changes to your environment, run at an agreed interval

Sample modules

Phishing to account compromise

An AI-written phishing email leads to stolen credentials and a suspicious sign-in. Analysts trace the message, the sign-in, and any mailbox rule changes.

Ransomware precursor activity

Discovery commands, credential dumping, and lateral movement appear in endpoint logs before encryption starts. Analysts identify the earliest useful signal.

Cloud identity misuse

A cloud access key is used from an unexpected location to list storage and create a new user. Analysts work from cloud audit logs.

Insider data movement

A user copies a large volume of files to a personal storage service. Analysts decide whether it is a policy breach, an error, or theft, and who to involve.

Alert from an AI security assistant

An AI feature in the security tooling flags an incident and writes a summary. Analysts check the summary against the logs and note what it missed or overstated.

Mixed alert queue

A queue of true and false positives. Analysts prioritize, close benign alerts with clear reasons, and escalate the cases that need it.

What you receive

Each engagement ends with written material your team can use after the sessions finish.

Debrief notes

  • Timeline of each scenario and the decisions analysts made
  • Evidence analysts found and evidence they missed
  • Points where escalation or handoff slowed down

Detection and log findings

  • Alerts that fired, did not fire, or fired without enough context
  • Log sources that were missing or hard to query
  • Suggested detection rule changes mapped to MITRE ATT&CK techniques

Runbook and process improvements

  • Recommended edits to triage and escalation runbooks
  • Gaps in case documentation templates
  • Ownership questions to settle between the SOC and other teams

Materials to rerun

  • Scenario briefs and facilitator notes
  • Synthetic datasets used in the lab
  • Expected findings so your team can run each exercise again

Common questions

Who should attend?

Tier 1 to tier 3 analysts, threat hunters, and detection engineers. SOC managers and shift leads can join the debriefs and tabletop sessions.

Do the exercises use our tools?

Scenarios are tailored to your environment and tools. We match the log formats, detection rules, and ticketing steps your analysts use, inside an isolated lab.

Is it remote or on-site?

Remote or on-site delivery can be agreed for each part of the program.

How do you measure progress?

Each exercise has written objectives and expected findings. The debrief records which objectives each group met. Running a similar scenario later shows whether the gaps have closed.

Can the program be repeated?

Yes. Scenario materials are handed over so your team can rerun them, and we can build new scenarios as your tools and the threats you face change.

How is our information protected?

Exercises use synthetic data in an isolated lab. We sign an NDA on request, and each engagement has a fixed, agreed scope.

How to prepare

Share a short description of your SOC: tiers and roles, main tools, log sources, and escalation path. A few alert types or past incidents that caused difficulty help us choose scenarios.

Name a contact who can confirm scope and answer questions during scenario design. Let analysts know the sessions are for practice and that the debrief looks at process and tooling as well as individual decisions.

Framework mapping

Scenarios and findings are described with MITRE ATT&CK techniques, so detection gaps can be compared with your existing coverage. Recommended defensive changes can reference MITRE D3FEND.

Learning objectives can be mapped to work roles in the NICE Framework, such as Defensive Cybersecurity, Incident Response, and Threat Analysis, to support role definitions and training plans.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.