COURSE DESCRIPTION
This immersive bootcamp prepares junior SOC analysts for the real world. Participants learn how a SOC operates, practice end-to-end incident handling, and gain core KQL skills in Microsoft Sentinel. Through CTF-style labs, they triage alerts, investigate phishing, endpoint malware, and cloud account compromise, document findings, and deliver a complete incident report, just like on the job.
LEARNING OUTCOMES
-
Explain SOC structure, roles (L1/L2/L3), tools (SIEM/EDR/SOAR), and key data sources.
-
Triage alerts efficiently, distinguish false positives, and prioritize risk.
-
Write and run effective KQL queries in Microsoft Sentinel for hunting and investigation.
-
Handle incidents end-to-end: containment, eradication, recovery, and documentation.
-
Investigate common scenarios: phishing → account takeover, endpoint malware.
-
Communicate clearly in tickets, handovers, and executive summaries.
CERTIFICATION
Graduates receive a Certificate of Completion: SOC Analyst Readiness (Level 1) from Black Swan Training Center, demonstrating practical skills in SOC workflows, KQL, and incident response.
Course Features
- Duration 2 day
- Skill level Beginner
- Language English
- Certification Yes
- 2 Sections
- 9 Lessons
- 2 Days
- Section: Day 1 — Foundations & Core Labs5
- 1.1Lesson 1.1: SOC in Microsoft — Roles, workflows, signal sources (Sentinel, Defender, Entra).
- 1.2Lesson 1.2: KQL Crash Course — Filters, time, parse, project, summarize.
- 1.3Lesson 1.3: Triage Workflow — Severity, enrichment, false vs. true positive.
- 1.4Lab A: KQL on Sentinel sample data — Find phishing, malware, and sign-in anomalies.
- 1.5Lab B: Incident in Sentinel — Investigate, contain, document a basic alert.
- Day 2 — Return, Q&A & Advanced Labs4
- 2.1Lesson 2.1: Field recap — what students tried at their company + Q&A.
- 2.2Lesson 2.2: Advanced KQL (ADX) — joins/union, parse_json, mv-expand, make-series, simple anomaly ideas.
- 2.3Lab C: Generate fresh telemetry — e.g., EICAR test, scheduled task creation, bulk failed logons; export to ADX.
- 2.4Lab D: Live log hunt in ADX — pivot across tables, build a timeline, derive IOAs/IOCs, write a short IR note (containment plan).
Requirements
- Laptop with a browser
Target audiences
- SOC analysts
- Junior incident responders





