image

Through hands-on labs and realistic scenarios, you’ll investigate sophisticated threats across enterprise environments, applying advanced techniques aligned with the MITRE ATT&CK framework. The curriculum emphasizes proactive threat hunting as part of a continuous detection and response cycle, helping analysts identify active threats, uncover security gaps, and improve future investigations.

By the end of the course, you'll be equipped with the mindset, tools, and methodologies needed to confidently investigate incidents, trace root causes, and respond effectively to advanced adversaries.

This course includes an Exam Vouchers for TCM Security’s Practical SOC Analyst Professional (PSAP) certification – Launching September 2025. Each exam voucher includes 1 exam attempt and is valid for 12-months from the course completion date or certification release date.

Develop a robust and reliable investigator's mindset to approach incidents methodically Learn industry-standard methodologies and tools for detecting, hunting, and responding to cyber threats across enterprise environments Gain experience performing incident response and threat hunting at scale Learn to investigate and identify advanced adversary tactics following the MITRE ATT&CK framework, including execution artifacts, lateral movement, credential theft, living off the land techniques, persistence, defense evasion, command and control, and many more Learn to perform effective attack timeline analysis, and guide effective incident response and remediation efforts Investigate the root cause of security incidents by uncovering the entry point
Virtual Instructor-Led Training 3 days / 24 hours

Who should attend SOC Level 2 Course

SOC 201 is designed for individuals seeking to advance their defensive security skills beyond foundational knowledge. Ideal candidates include those already familiar with core SOC concepts who are ready to develop expertise in investigating and responding to sophisticated cyber threats. This course is suited for Tier 2 Security/SOC Analysts, Tier 3 Security/SOC Analysts, Incident Responders, Threat Hunters, Digital Forensic Examiners.

Prerequisites for SOC Level 2 Course

This course relies heavily on working with IR investigations and forensic artifacts, but does not cover learning basic analysis tools. It is strongly recommended to have taken or be familiar with the Security Operations (SOC) 101 material and its prerequisites, which includes experience with: Networking Fundamentals: Practical Help Desk (PHD) or equivalent Operating System Fundamentals: Practical Help Desk (PHD) or equivalent Security Operations Fundamentals Network Traffic Analysis Endpoint Security Monitoring Log Analysis and Management Security Information and Event Management (SIEM) Basic Digital Forensics Exposure

SOC Level 2 Course Outline


Resources

FAQs on SOC Level 2

SOC 201 is designed for Tier 2 and Tier 3 Security/SOC Analysts, Incident Responders, Threat Hunters, and Digital Forensic Examiners who already have foundational SOC knowledge and want to advance their defensive security skills.

Participants should have completed SOC 101 or possess equivalent experience, including Networking and Operating System Fundamentals, Security Operations Fundamentals, Network Traffic Analysis, Endpoint Security Monitoring, Log Analysis, SIEM experience, and basic digital forensics exposure. This course does not cover basic analysis tools.

You will develop an investigator’s mindset for methodical incident response, learn industry-standard threat hunting and detection methodologies, and gain hands-on experience investigating advanced adversary tactics using the MITRE ATT&CK framework, including lateral movement, credential theft, persistence, and defense evasion.

The course covers modern adversary tactics, incident response fundamentals, and threat hunting methodologies on Day 1, followed by anomaly detection techniques, threat report analysis, and hands-on labs for hunting execution, persistence, defense evasion, and command and control activities on Day 2.

You will learn to perform effective attack timeline analysis, investigate root causes of security incidents by identifying entry points, and conduct incident response and threat hunting at enterprise scale using real-world forensic artifacts and structured investigative techniques.