Foundations and the first alert
The cohort opens with the environment every later session builds on: how a SOC actually receives work, what an alert queue looks like under load, and the first signal of the breach that will take the next six Saturdays to unravel.
- When
- Sat 17 Oct 2026 · 10:30–13:30 IST
- Where
- Bangalore or virtual
- Cohort size
- 25 in person · 40 including virtual
Sessions can be booked individually, or take the full six-session cohort.
What you leave able to do
- Work a live alert queue and defend your triage order
- Read the first indicators of the Noowapay intrusion
- Set up the lab environment used across all six sessions
Run of play
- 1
How a SOC receives work
Queues, severities, and why the loudest alert is rarely the one that matters.
- 2
First contact
The opening signal of the breach, worked live.
The case
Where this sits in the story
All six Saturdays run on one continuous breach, so every session picks up where the last one left off.
Three weeks before you arrive, a four-minute anomaly hits NoowaPay's network at 02:47 and the grid team calls it a glitch. Nobody yet knows it was Silent Phantom's first touch. Session 1 is your orientation and your first shift: the SSH noise on a bastion host that has Klaus uneasy, because it has the same patient, low-and-slow shape.
Who this session suits
Career switchers and IT professionals moving into security. No prior SOC experience assumed — this is the session that builds the floor everything else stands on.
Scope
What this session covers
- What a SOC is for, and how detect/analyse/respond actually divide up
- Analyst tiers, escalation, and why alert fatigue is a staffing problem
- NIST CSF as the map analysts classify their work against
- The NoowaPay stack: SIEM, EDR, SOAR and the log sources feeding them
- Reading /var/log/auth.log and proving whether a brute force succeeded
- grep, awk, sort and uniq as the analyst's core toolkit
- Correlating one attacker across syslog, Apache, firewall and JSON logs
Hands-on
The labs you work
7 hands-on labs, 265 minutes of lab time. Each runs in a cloud terminal against real evidence — logs, PCAPs, event data — and is graded on what you find, not on a multiple-choice answer. Lab access continues for 3 months, so the work does not stop when the session ends.
- 1SOC Roles & Analyst Tierssoc-orientation20 min
- 2What is a SOC?soc-orientation25 min
- 3NIST CSF & Security Frameworkssoc-orientation20 min
- 4The NoowaPay Tech Stacksoc-orientation20 min
- 5Chapter 1: Your First Shiftsoc-foundations55 min
- 6Linux CLI for SOC Analystssoc-foundations75 min
- 7Log Analysis 101soc-foundations50 min
Tools used
- Linux CLI
- grep / awk / sed
- jq
- auth.log
- syslog
- Apache access logs
MITRE ATT&CK coverage (16)
- T1003 OS Credential Dumping
- T1033 System Owner/User Discovery
- T1036 Masquerading
- T1046 Network Service Discovery
- T1048 Exfiltration Over Alternative Protocol
- T1057 Process Discovery
- T1078 Valid Accounts
- T1083 File and Directory Discovery
- T1110 Brute Force
- T1110.001 Brute Force: Password Guessing
- T1119 Automated Collection
- T1190 Exploit Public-Facing Application
- T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching
- T1562 Impair Defenses
- T1588 Obtain Capabilities
- T1595 Active Scanning
Schedule
The full cohort
One continuous case across six Saturdays. Sessions build on each other, and each one can also be booked on its own.
- Sat 17 Oct 2026Foundations and the first alert10:30–13:30 ISTYou are here
- Sat 24 Oct 2026AI-era phishing and the initial foothold10:30–13:30 ISTDetails →
- Sat 31 Oct 2026Endpoint investigation and containment10:30–13:30 ISTDetails →
- Sat 7 Nov 2026Diwali holiday — no sessionNo session
- Sat 14 Nov 2026Cloud SOC and lateral movement10:30–13:30 ISTDetails →
- Sat 21 Nov 2026Detection engineering and automation10:30–13:30 ISTDetails →
- Sat 28 Nov 2026Immersive day and certification exam10:30–17:30 IST · full dayDetails →
Taking the whole cohort?
The six sessions are one continuous case, and the full course page carries the curriculum, the certification detail and the cohort pricing.

