Phishing & Business Email Compromise
Trace credential theft via MDO alerts, analyze headers, and contain compromised mailboxes before lateral movement begins.
Train with real enterprise tools. Work real incidents. Graduate with a portfolio employers can evaluate on day one.
SecurityEvent | where EventID == 4769 | summarize requests=count() by Account | where requests > 50▌
No toy labs. You'll investigate, triage, and respond using the same platforms deployed in Fortune 500 security operations centers.
Each phase builds on the last — from SOC fundamentals to leading live incidents and executing your capstone shift.
Orient yourself inside a production SOC. Master alert triage workflows, platform navigation, and incident classification before touching a live case.
Every module ends with a documented investigation — building the portfolio that gets you past the HR screen and into the technical interview.
Trace credential theft via MDO alerts, analyze headers, and contain compromised mailboxes before lateral movement begins.
Detect anomalous Kerberos activity in Sentinel, correlate with MDI signals, and execute identity containment playbooks.
Hunt living-off-the-land techniques using MDE advanced hunting queries and CrowdStrike Falcon telemetry.
Lead end-to-end containment, draft executive communications, and present findings in a simulated board-level briefing.
Operate a full 8-hour shift: triage the queue, escalate P1s, write KQL detections, and hand off to the next analyst.
Schedule a 30-minute call with an admissions advisor. We'll walk you through the program and how it can help you become a SOC analyst.
Ask us anything about the program, cohorts, or admissions — we'll get back to you within 48 hours.