
TRAINING / SIT
- Defensive security
- Intermediate
SOC Immersion Training.
Investigate adversary activity across host and network evidence. Build an analysis method your team can use beyond the course.
- Duration
- 5 days
- Level
- Intermediate
- Delivery
- In-person / Remote
- Completion
- Accredible certificate
Analysis & detection
Course overview.
SOC Immersion Training develops an evidence-led approach to intrusion analysis. Students work through adversary activity and examine the network, event log, memory, and registry artifacts it leaves behind.
The course introduces our Layered Analysis Methodology, then applies it to initial access, persistence, privilege escalation, and lateral movement. Instructor demonstrations and range exercises connect each technique to the evidence an analyst can use. The emphasis is on explaining activity and improving detection, rather than memorizing a particular tool.
Who it is for
- SOC and hunt team analysts
- Detection engineers
- Security analysts investigating intrusions
Tools and concepts
- Sysmon
- Suricata
- Network traffic analysis
- Windows event logs
- Host and memory artifacts
Learning outcomes
What your team will practice.
Correlate alerts with host and network evidence to form and test an investigative hypothesis.
Recognize the artifacts left by common initial-access techniques.
Identify changes that allow an adversary to retain access.
Trace privilege changes and separate supporting evidence from assumptions.
Reconstruct movement between hosts and use the findings to refine detection.
Curriculum
Inside the course.
Topics covered across five days of instructor-led training.
01Analysis methodology
Correlate alerts with host and network evidence to form and test an investigative hypothesis.
- Attack lifecycle and Tradecraft Core Concepts
- Network, log, memory, and registry evidence
- Layered Analysis Methodology
02Initial access evidence
Recognize the artifacts left by common initial-access techniques.
- Document and browser activity
- Web-shell evidence
- Tracing an alert back to an entry point
03Persistence analysis
Identify changes that allow an adversary to retain access.
- Registry and service changes
- Group Policy activity
- Correlating persistence evidence across data sources
04Privilege escalation analysis
Trace privilege changes and separate supporting evidence from assumptions.
- Service abuse and misconfiguration
- User Account Control boundaries
- Local and remote privilege changes
05Lateral movement and detection
Reconstruct movement between hosts and use the findings to refine detection.
- Remote execution and management activity
- Cross-host evidence correlation
- Indicators and detection refinement
Preparation
Before your team attends.
Prerequisites
- Working knowledge of Windows and Linux fundamentals.
- Familiarity with network traffic, event logs, and security alerts.
What to bring
- A laptop, charger, and a modern web browser.
- Internet access suitable for connecting to the training environment.
What is included
- Instructor-led demonstrations and guided lab exercises.
- Course reference materials.
- An Accredible certificate of completion.
The training team
Meet your instructors.

Alexander Rymdeko-Harvey
Co-Founder, Chief Executive Officer (CEO)

Keelyn Roberts
Co-Founder, Chief Operating Officer (COO)

Tory Clasen
Chief Technology Officer (CTO)
Workforce alignment
NICE Framework alignment.
Course objectives align with selected parts of the NICE Framework, version 2.2.0. This is a curriculum alignment, not full work-role qualification or NIST endorsement.
- Defensive CybersecurityPD-WRL-001
- Digital ForensicsPD-WRL-002
View curriculum alignment
The course-specific Layered Analysis Methodology and Tradecraft Core Concepts are not separate NICE competencies.
Analysis methodology
Correlate alerts with host and network evidence to form and test an investigative hypothesis.
Related work roles: Defensive Cybersecurity (PD-WRL-001); Digital Forensics (PD-WRL-002)
- tasks
- T1103Analyze intrusions
- T1387Validate intrusion detection system alerts
- knowledge
- K0696Knowledge of digital forensic data principles and practices
- K0732Knowledge of intrusion detection tools and techniques
- skills
- S0505Skill in performing intrusion data analysis
- S0866Skill in performing log file analysis
Alert validation and evidence correlation align with intrusion analysis; the named teaching methodology is specific to this course.
Initial access evidence
Recognize the artifacts left by common initial-access techniques.
Related work roles: Defensive Cybersecurity (PD-WRL-001); Digital Forensics (PD-WRL-002)
- tasks
- T0845Identify cyber threat tactics and methodologies
- T1370Collect intrusion artifacts
- knowledge
- K0845Knowledge of cyber intrusion activity phases
- K0696Knowledge of digital forensic data principles and practices
- skills
- S0481Skill in identifying forensic digital footprints
The objective concerns identifying adversary techniques and the digital evidence they leave, not carrying out initial access.
Persistence analysis
Identify changes that allow an adversary to retain access.
Related work roles: Digital Forensics (PD-WRL-002)
- tasks
- T1103Analyze intrusions
- T1370Collect intrusion artifacts
- knowledge
- K0845Knowledge of cyber intrusion activity phases
- K0897Knowledge of logging tools and technologies
- skills
- S0481Skill in identifying forensic digital footprints
- S0866Skill in performing log file analysis
Students examine persistence artifacts and logs to explain intrusion activity.
Privilege escalation analysis
Trace privilege changes and separate supporting evidence from assumptions.
Related work roles: Digital Forensics (PD-WRL-002)
- tasks
- T1103Analyze intrusions
- knowledge
- K0686Knowledge of authentication and authorization tools and techniques
- K0696Knowledge of digital forensic data principles and practices
- skills
- S0505Skill in performing intrusion data analysis
- S0481Skill in identifying forensic digital footprints
This module maps the analysis of privilege changes, not the full administration of access controls.
Lateral movement and detection
Reconstruct movement between hosts and use the findings to refine detection.
Related work roles: Defensive Cybersecurity (PD-WRL-001); Digital Forensics (PD-WRL-002)
- tasks
- T1103Analyze intrusions
- T1406Construct cyber defense network tool signatures
- knowledge
- K0845Knowledge of cyber intrusion activity phases
- K0732Knowledge of intrusion detection tools and techniques
- skills
- S0505Skill in performing intrusion data analysis
- S0566Skill in developing signatures
Correlating movement supports intrusion analysis; converting findings into detection logic supports signature development.
Bring SIT to your team.
Tell us your team size, preferred dates, and delivery format. Include SIT in your inquiry.
