16-Week Program

The full curriculum,
week by week.

From your first packet capture to a live two-week SOC simulation. Every week builds directly on the last.

16
Weeks
80%
Hands-on labs
6
Phases
75+
Simulated alerts
PHASE 0
Cyber Foundations
Weeks 1–2
No experience required. Build the mental model every analyst carries into every investigation.
Week 1
How the Internet Works & Networking Basics
  • IP addresses, DNS, HTTP/HTTPS, ports, and packets
  • The OSI model — each layer and its role in investigations
  • TCP vs UDP and why the difference matters
  • Live Wireshark capture — trace traffic from source to destination
Week 2
Operating Systems & Security Concepts 101
  • Windows Event IDs analysts check every day: 4624, 4625, 4688
  • Linux CLI fundamentals — navigating, processes, permissions
  • CIA Triad applied to real breach scenarios
  • Threat, vulnerability, risk, and exploit — the language of the SOC
PHASE 1
Security Fundamentals
Weeks 3–4
Learn how attackers operate and how defenders respond — the conceptual foundation for everything in the lab phases.
Week 3
Attack Types, Threat Landscape & Phishing Analysis
  • Malware taxonomy: ransomware, RATs, trojans, spyware
  • Phishing variants and social engineering psychology
  • Indicators of Compromise (IOCs) — what they are and where to find them
  • Analyse 5 real phishing samples — headers, spoofed domains, obfuscated URLs
Week 4
Defensive Tools, Cryptography & Compliance
  • Firewall, IDS/IPS, EDR, XDR — what each tool can and cannot see
  • Hashing and encryption — why they matter to analysts, not engineers
  • NIST CSF, HIPAA, PCI-DSS — what compliance shapes in a SOC
  • Map a real breach to NIST's five functions
PHASE 2
SOC Environment
Weeks 5–6
Step inside the SOC. Connect your own Sentinel tenant and triage your first real alerts under SLA pressure.
Week 5
SOC Roles, Structure & SIEM Fundamentals
  • L1 / L2 / L3 analyst roles — responsibilities, escalation paths, shift handover
  • How a SIEM works: log ingestion, normalisation, correlation, alerting
  • Connect your M365 E5 tenant to Microsoft Sentinel for the first time
  • Write 5 KQL queries — failed logins, new accounts, top source IPs
Week 6
Alert Triage Workflow & Ticketing
  • The 5-step triage process used in MSSP environments
  • TP / FP / BTP — classifications that define your L1 day
  • Triage sprint: 10 alerts, 30 minutes, SLA clock running
  • Write production-quality incident tickets in ServiceNow
PHASE 3
Hands-On Labs
Weeks 7–12
Six weeks of deep tool work across the full Microsoft Defender XDR stack. Each week adds a new attack surface.
Week 7
Sentinel Analytics Rules & Advanced KQL
  • Build a custom analytics rule from scratch and test it live
  • Investigate a multi-alert incident from open to closed
  • Advanced KQL: joins, summarise, let statements
Week 8
Entra ID, Defender for Identity & Credential Attacks
  • Detect and investigate a password spray and an MFA fatigue attack
  • Work a Defender for Identity DCSync alert end-to-end
  • Recommend a Conditional Access policy that prevents the attack
Week 9
Defender for Endpoint & EDR Investigation
  • Decode a Base64 PowerShell command and determine intent
  • Isolate a confirmed malware device and write the containment ticket
  • Threat & Vulnerability Management — prioritise CVEs by exposure
Week 10
Defender for Office 365 & Cloud Apps
  • Investigate a Business Email Compromise — trace, contain, document
  • Identify shadow IT and draft a block policy using MDCA
  • Audit OAuth app permissions and flag high-risk consents
Week 11
Threat Intelligence & MITRE ATT&CK
  • Map a real APT group's TTPs in ATT&CK Navigator
  • Enrich 10 IOCs across VirusTotal, OTX, and AbuseIPDB
  • Import a threat watchlist into Sentinel and build a firing rule
Week 12
Log Analysis, Malware Triage & Incident Response
  • Reconstruct a full attack timeline from a 72-hour Event Log export
  • Static malware analysis — strings, PE headers, VirusTotal
  • Ransomware IR tabletop — rotate through every lifecycle role
Phase 4 — Weeks 13 & 14
Operation Nightwatch
A two-week live SOC simulation. Real alert volume. Real SLA pressure. An active APT intrusion that evolves across both weeks. No hints. No guidance. Your tools, your playbooks, your decisions.
75+
Alerts across both weeks
6
Shift blocks
4
Scoring categories
P1
Active incident, Week 13 Day 1
PHASE 5
Job Readiness & Graduation
Weeks 15–16
Your 14 weeks of work becomes a hiring package. Interviews, portfolio, final assessment, certificate.
Week 15
Resume, Portfolio & Technical Interviews
  • Group resume review — every student gets honest, specific feedback
  • Publish 3 lab write-ups as GitHub portfolio projects during this session
  • 45-minute mock technical interview per student with the instructor
  • Salary negotiation roleplay — take a first offer from $55K to $65K
Week 16
Final Assessment, Certification & What Comes Next
  • 2-hour solo final assessment — all tools, no assistance
  • Peer teaching: each student teaches the concept they found hardest
  • 30-60-90 day job search plan built individually
  • CyberPrime Certificate of Completion presented
What you can do on Day 1 of your first job.
The competency standard every CyberPrime graduate meets before they leave the program.
Triage 30+ alerts per shift and classify each accurately
Investigate alerts across identity, endpoint, email, and cloud
Write KQL queries in Sentinel to hunt for specific threats
Document incidents in ServiceNow at MSSP client standard
Map adversary behaviour to MITRE ATT&CK techniques
Execute L1 containment — isolate, revoke, disable — without prompting
Manage a full shift queue under SLA pressure
Explain findings clearly to both technical and non-technical audiences