Skip to main content

Explore how SIEM solutions help detect early signs of attacks, investigate SOC alerts, and correlate logs to build an incident timeline.

In this module, you will learn to apply a systematic approach to SIEM investigations: where to focus your attention, and which queries to run to get the answers quickly. You will investigate various scenarios in Splunk and Elastic across web, Linux, and Windows environments, sharpening the triage skills, which every SOC analyst needs to succeed.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.