TRAINING / SIT

  • Defensive security
  • Intermediate

SOC Immersion Training.

Investigate adversary activity across host and network evidence. Build an analysis method your team can use beyond the course.

Duration
5 days
Level
Intermediate
Delivery
In-person / Remote
Completion
Accredible certificate

Analysis & detection

Course overview.

SOC Immersion Training develops an evidence-led approach to intrusion analysis. Students work through adversary activity and examine the network, event log, memory, and registry artifacts it leaves behind.

The course introduces our Layered Analysis Methodology, then applies it to initial access, persistence, privilege escalation, and lateral movement. Instructor demonstrations and range exercises connect each technique to the evidence an analyst can use. The emphasis is on explaining activity and improving detection, rather than memorizing a particular tool.

Who it is for

  • SOC and hunt team analysts
  • Detection engineers
  • Security analysts investigating intrusions

Tools and concepts

  • Sysmon
  • Suricata
  • Network traffic analysis
  • Windows event logs
  • Host and memory artifacts

Learning outcomes

What your team will practice.

  • Correlate alerts with host and network evidence to form and test an investigative hypothesis.

  • Recognize the artifacts left by common initial-access techniques.

  • Identify changes that allow an adversary to retain access.

  • Trace privilege changes and separate supporting evidence from assumptions.

  • Reconstruct movement between hosts and use the findings to refine detection.

Curriculum

Inside the course.

Topics covered across five days of instructor-led training.

01

Analysis methodology

Correlate alerts with host and network evidence to form and test an investigative hypothesis.

  • Attack lifecycle and Tradecraft Core Concepts
  • Network, log, memory, and registry evidence
  • Layered Analysis Methodology
02

Initial access evidence

Recognize the artifacts left by common initial-access techniques.

  • Document and browser activity
  • Web-shell evidence
  • Tracing an alert back to an entry point
03

Persistence analysis

Identify changes that allow an adversary to retain access.

  • Registry and service changes
  • Group Policy activity
  • Correlating persistence evidence across data sources
04

Privilege escalation analysis

Trace privilege changes and separate supporting evidence from assumptions.

  • Service abuse and misconfiguration
  • User Account Control boundaries
  • Local and remote privilege changes
05

Lateral movement and detection

Reconstruct movement between hosts and use the findings to refine detection.

  • Remote execution and management activity
  • Cross-host evidence correlation
  • Indicators and detection refinement

Preparation

Before your team attends.

Prerequisites

  • Working knowledge of Windows and Linux fundamentals.
  • Familiarity with network traffic, event logs, and security alerts.

What to bring

  • A laptop, charger, and a modern web browser.
  • Internet access suitable for connecting to the training environment.

What is included

  • Instructor-led demonstrations and guided lab exercises.
  • Course reference materials.
  • An Accredible certificate of completion.

The training team

Meet your instructors.

Workforce alignment

NICE Framework alignment.

Course objectives align with selected parts of the NICE Framework, version 2.2.0. This is a curriculum alignment, not full work-role qualification or NIST endorsement.

  • Defensive CybersecurityPD-WRL-001
  • Digital ForensicsPD-WRL-002
View curriculum alignment

The course-specific Layered Analysis Methodology and Tradecraft Core Concepts are not separate NICE competencies.

  1. Analysis methodology

    Correlate alerts with host and network evidence to form and test an investigative hypothesis.

    Related work roles: Defensive Cybersecurity (PD-WRL-001); Digital Forensics (PD-WRL-002)

    tasks
    • T1103Analyze intrusions
    • T1387Validate intrusion detection system alerts
    knowledge
    • K0696Knowledge of digital forensic data principles and practices
    • K0732Knowledge of intrusion detection tools and techniques
    skills
    • S0505Skill in performing intrusion data analysis
    • S0866Skill in performing log file analysis

    Alert validation and evidence correlation align with intrusion analysis; the named teaching methodology is specific to this course.

  2. Initial access evidence

    Recognize the artifacts left by common initial-access techniques.

    Related work roles: Defensive Cybersecurity (PD-WRL-001); Digital Forensics (PD-WRL-002)

    tasks
    • T0845Identify cyber threat tactics and methodologies
    • T1370Collect intrusion artifacts
    knowledge
    • K0845Knowledge of cyber intrusion activity phases
    • K0696Knowledge of digital forensic data principles and practices
    skills
    • S0481Skill in identifying forensic digital footprints

    The objective concerns identifying adversary techniques and the digital evidence they leave, not carrying out initial access.

  3. Persistence analysis

    Identify changes that allow an adversary to retain access.

    Related work roles: Digital Forensics (PD-WRL-002)

    tasks
    • T1103Analyze intrusions
    • T1370Collect intrusion artifacts
    knowledge
    • K0845Knowledge of cyber intrusion activity phases
    • K0897Knowledge of logging tools and technologies
    skills
    • S0481Skill in identifying forensic digital footprints
    • S0866Skill in performing log file analysis

    Students examine persistence artifacts and logs to explain intrusion activity.

  4. Privilege escalation analysis

    Trace privilege changes and separate supporting evidence from assumptions.

    Related work roles: Digital Forensics (PD-WRL-002)

    tasks
    • T1103Analyze intrusions
    knowledge
    • K0686Knowledge of authentication and authorization tools and techniques
    • K0696Knowledge of digital forensic data principles and practices
    skills
    • S0505Skill in performing intrusion data analysis
    • S0481Skill in identifying forensic digital footprints

    This module maps the analysis of privilege changes, not the full administration of access controls.

  5. Lateral movement and detection

    Reconstruct movement between hosts and use the findings to refine detection.

    Related work roles: Defensive Cybersecurity (PD-WRL-001); Digital Forensics (PD-WRL-002)

    tasks
    • T1103Analyze intrusions
    • T1406Construct cyber defense network tool signatures
    knowledge
    • K0845Knowledge of cyber intrusion activity phases
    • K0732Knowledge of intrusion detection tools and techniques
    skills
    • S0505Skill in performing intrusion data analysis
    • S0566Skill in developing signatures

    Correlating movement supports intrusion analysis; converting findings into detection logic supports signature development.

NIST NICE Framework source data

Bring SIT to your team.

Tell us your team size, preferred dates, and delivery format. Include SIT in your inquiry.