AI SOC Analyst: Weekend Cohort
Six Saturday mornings. Both sides of the AI shift — the attacks and the tooling — investigated end to end on real enterprise consoles.
6 weekends
Saturdays, 10:30–13:30
47 lessons
Full lab course included, 3 months
18 CISOs
Curriculum reviewed by
100%
Hands-on, no slideware
Maps to the domains of
EC-Council CSA
CySA+40% off the release price. Includes 3 months of lab access, and certification with 2 attempts (worth ₹10,000) free with the full cohort. Booking single Saturdays instead? Certification can be added to any session for ₹10,000.
Book the Full CohortSee the Full Lab CourseThis course includes
- 5 live sessions plus 1 immersive day, Saturdays 10:30–13:30
- 3 months of access to the full 40-chapter lab course, including the 72-hour Siege capstone
- Arcs M3 and M4 taught live in full — every lesson and micro-project
- Instructor-led cohort, Bangalore or virtual
- A downloadable incident report from every lesson and micro-project
- Certification included — 2 attempts within 3 months of finishing
- Maps to CompTIA Security+, ISC2 CC, and CompTIA SecAI+ domains
- Cloud labs on real Sentinel, AWS and Azure consoles — no local setup
What You’ll Learn
Skills You’ll Gain
What is taught live, and what is in the lab
Enrolment buys two things. The six Saturdays are instructor-led and cover the AI and cloud half of the syllabus. The same enrolment also opens the full AI SOC Analyst lab course on labs.cybe.global for three months, which is larger than what the live sessions cover and is worked in your own time.
Live instructor sessions
6 Saturdays · 34 lessonsTaught in the room or on the call, with an instructor working the case alongside the cohort. This is the schedule listed below.
- Arc M3, AI-Era Threat Investigation, in full — AI phishing, prompt injection against Copilot, Slack AI and ServiceNow, deepfake and voice-clone cases, UEBA bypass, adversarial ML
- Arc M4, AI-Era Cloud SOC, in full — cloud log sources, IAM privilege escalation, S3 exfiltration, Lambda persistence, cross-cloud lateral movement, SOAR automation
- The 7 foundation lessons from arcs M0 to M2 that M3 and M4 formally require: Linux CLI, log analysis, KQL, incident reporting, AD credential forensics
- The Cyber War Room immersive day and the certification exam, both on Saturday 28 November
- The other 20 foundation lessons in arcs M1 and M2 — endpoint triage, YARA, EVTX parsing, threat intel and Sentinel analytics rules — which are in the lab, not the live sessions
- The 72-hour Siege capstone, which runs self-paced in the lab
Self-paced lab course
3 months · 47 lessonsThe complete AI SOC Analyst programme on labs.cybe.global, unchanged and unabridged. Included with enrolment and open for three months from the final Saturday.
- All 47 lessons across the 5 arcs plus Siege, including every lesson the live sessions do not reach
- The full 72-hour SOC Siege capstone, graded by practising security leaders
- 14 micro-projects, each a named real-world case worked from the artifacts
- 63 portfolio artifacts, mapped across 174 MITRE ATT&CK techniques
- A live terminal lab environment on real Sentinel, AWS and Azure consoles
The two run on the same continuous 33-day Noowapay breach, so lab chapters worked between Saturdays feed directly into the next live session rather than sitting apart from it.
Curriculum
6 modules · 34 lessons
- What is a SOC?Preview25 min
- Your First Shift35 min
- Linux CLI for SOC Analysts75 min
- Log Analysis 10150 min
Upcoming cohort dates
One cohort, six Saturday sessions. Half-day sessions run 10:30–13:30; the closing immersive day runs 10:30–17:30. Attend in Bangalore or join virtually.
Bangalore / Virtual
- 1Sat 17 OctLive session · 10:30–13:30
- 2Sat 24 OctLive session · 10:30–13:30
- 3Sat 31 OctLive session · 10:30–13:30
- Sat 7 NovDiwali holiday — no session
- 4Sat 14 NovLive session · 10:30–13:30
- 5Sat 21 NovLive session · 10:30–13:30
- 6Sat 28 NovExam dayImmersive day and certification exam · 10:30–17:30
Lab access runs for 3 months. Certification allows 2 attempts within 3 months of the final session.
Individual sessions can also be booked on their own — ₹2,700 for a half-day session, or ₹3,600 for the full-day immersive that includes the Cyber War Room. Follow any date above to book it.
Only need one part of this?
Each Saturday is a self-contained capability — phishing triage, endpoint forensics, cloud and SOAR — and can be booked on its own without joining the cohort. Every session page carries its own labs, ATT&CK coverage and price.
Compare the six sessions →What backs this up
The specifics behind the claims on this page. Open any of them for the detail.
- Day 0
Before the Storm
Analyst onboarding and SOC mission, before any alert fires. Learn the stack and the threat landscape.
- Days 1-6
The First Sign
An overnight SSH anomaly and unusual process activity. Triage it, run Linux CLI forensics, write your first incident ticket.
- Days 7-14
The Hook
A phishing email, four clicks, a C2 beacon and 23 queued alerts. Analyse AI-written phishing headers, trace the beacon, isolate the endpoint.
- Days 13-19
The Command Centre
The domain controller is reached and a maldoc surfaces. Write KQL in Microsoft Sentinel, detect DCSync, reverse the macro.
- Days 20-26
The Machine Learns to Lie
LLM prompt injection, AI phishing, UEBA bypass and ML poisoning, detected against MITRE ATLAS.
- Days 27-33
Cloud Nine, Ground Zero
An AWS admin role assumed, S3 exfiltrated and a Lambda backdoor left behind.
SSH Brute Force Triage
Noowapay Day 2 — the first anomaly, from detection through to a written ticket.
AI Phishing Header Analysis
Noowapay Day 9 — dissecting an AI-written phishing email at header level.
Every report ATT&CK-mapped
174 distinct techniques across the full set, so the portfolio speaks the language SOC hiring managers screen on.
Breach response under the clock
A continuous 72-hour scenario, not a quiz. Worked in the lab, in your own time, within the 3-month access window.
Graded by practitioners
Reviewed by practising security leaders from the advisory panel.
The live counterpart
The Cyber War Room on Saturday 28 November is the instructor-led containment exercise; the Siege is the longer self-paced one.
- Hiring
AuthenticOne, Aishan Technologies, CyBe Global, CSA Bangalore Chapter
- Advisory
Reviewed by an advisory panel of practising security leaders
The full roster, with roles and organisations, is listed at /course-advisors.
- Track record
Run as workshops and events with academic and community partners
Delivered with CSA Bangalore Chapter and partner institutions rather than as an untested launch.
Who Should Attend
Graduates & Career Switchers
Fresh graduates, career switchers, and IT support, helpdesk or NOC staff moving into a Tier-1 SOC analyst role — provided you are already comfortable with a terminal and basic log triage.
Working L1/L2 Analysts
SOC analysts already on the queue who have not yet worked an AI-era or cloud-native incident end to end, and want the 2024–2025 attacker techniques their existing training skipped.
Corporate & Campus Cohorts
Teams training together ahead of a SOC hire, internship, or internal role transition. The format is built for a cohort of 12–20 learning as a group, not for self-paced study.
How You’ll Be Certified
Ground
Sessions 1 to 3 carry only the foundation lessons M3 and M4 formally depend on — Linux CLI, log analysis, KQL, incident reporting, and AD credential forensics. The other 20 foundation lessons in arcs M1 and M2 are left out of the live sessions and worked in the lab course instead.
7 of 27 foundation lessons taught live
Investigate
Sessions 2 to 4 deliver AI-Era Threat Investigation in full: AI phishing, prompt injection against Copilot, Slack AI and ServiceNow, deepfake and voice-clone cases, UEBA bypass, and adversarial ML.
Arc M3 · every lesson and micro-project, taught live
Hunt in the Cloud
Sessions 4 to 6 run AI-Era Cloud SOC end to end — cloud log sources, IAM privilege escalation, S3 exfiltration, Lambda persistence, cross-cloud lateral movement, and SOAR automation.
Arc M4 · every lesson and micro-project, taught live
Leave With a Portfolio
Every lesson and micro-project produces a downloadable incident report. You finish with a body of investigation work a recruiter can open and read — not a quiz score. The only assessment across the six Saturdays is the certification exam on the final immersive day.
Portfolio of incident reports
How this maps to certification domains
The six sessions are not exam prep and the credential you earn is CyBe’s own. These counts come from mapping each session in the schedule above against the awarding bodies’ published exam objectives — including the domains this programme does not cover, which are named rather than omitted.
| Body | Certification | Domains mapped | Why it matters |
|---|---|---|---|
Microsoft Security Operations Analyst (SC-200) SC-200 | 3 of 3 | All three functional groups: managing the environment, incident response, and KQL threat hunting — taught on live Sentinel. | |
![]() | EC-Council Certified SOC Analyst (312-39) EC-Council CSA | 7 of 8 | 7 of 8 modules. Malware reverse-engineering is out of scope here; the forensics and cloud-SOC modules are covered in depth. |
![]() | CompTIA Cybersecurity Analyst (CySA+) CySA+ | 3 of 4 | 3 of 4 domains: security operations, incident response, and reporting. Vulnerability management is not part of this programme. |
Microsoft Security Operations Analyst (SC-200)
All three functional groups: managing the environment, incident response, and KQL threat hunting — taught on live Sentinel.
7 of 8EC-Council Certified SOC Analyst (312-39)
7 of 8 modules. Malware reverse-engineering is out of scope here; the forensics and cloud-SOC modules are covered in depth.
3 of 4CompTIA Cybersecurity Analyst (CySA+)
3 of 4 domains: security operations, incident response, and reporting. Vulnerability management is not part of this programme.
Certification names and logos are the property of their respective owners and are used here only to identify the credentials this curriculum maps to. CyBe Global is not affiliated with, endorsed by or accredited by Microsoft, EC-Council or CompTIA, and this programme is not an official preparation course for any of their exams. EC-Council logo: Wikimedia Commons, CC BY-SA 4.0.
Faculty for This Course
Satyavathi Divadari
CEO & Founder · CyBe Global / CSA Bangalore
Madhukeshwar Bhat
Academia Advisor · CSA Bangalore Chapter
Course Advisors
Practising security leaders who review this curriculum and keep it current.

R S Lakshminarayanan
GM & Regional CISO · Wipro Limited

Ravi Subbiah
Managing Partner · TCS Ltd

Vishal Saraswat
Head, Research & Innovation, Cybersecurity · Bosch Software

Sai Lakshmi Sathyanarayana
Partner, Cyber Leader · EY GDS
What Learners Say
“This was different learning experience all together. So much fun and so much to learn. The energy was continuously high to know what’s next. Not just regular content but every time something new and different. I recommend this learning methodology to every learner.”
Pravinkumar Jha
Head of Product and Cloud Security
“That sounds like such a refreshing change from usual conferences. Learning through music and teamwork really makes complex concepts stick in a fun way.”
Rohan Pinto
CTO and Founder, 1Kosmos
