Group Purchasing
Group Purchasing
AI SKILLSMAJOR UPDATES

SEC450: AI-Enabled Security Operations: Hands-on Investigation, Detection, and Automation

SEC450Cyber Defense, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
John Hubbard
John Hubbard
SEC450: Blue Team Fundamentals: Security Operations and Analysis
Course authored by:
John Hubbard
John Hubbard
  • GIAC Security Operations Certified (GSOC)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 19 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn how to detect, triage, investigate, automate, and improve SOC operations using practical analyst skills and AI-enabled workflows while keeping evidence and human judgment at the center.

Course Overview

SEC450 teaches practical SOC analysis for modern cyber defense: detection, triage, investigation, and detection engineering using SIEM, EDR/XDR, threat intelligence, and AI-assisted workflows. Students build the evidence discipline and judgment to make fast, defensible security decisions.

A Practical SOC Analyst Course Built for the AI Era

Security Operations Centers are under pressure from growing telemetry volume, more complex attacks, constant alert noise, and increasing expectations for speed. At the same time, AI-assisted tools and agentic workflows are becoming part of the SOC toolset. Analysts need to understand what these systems can do, where they fit, where they fail, and how to keep human judgment at the right decision points.

This course teaches SOC analysis as an end-to-end operational discipline. Students start with the mission and scope of the SOC, then learn how to use security tools, threat intelligence, network evidence, endpoint logs, email artifacts, file and malware indicators, structured investigation methods, and detection engineering to reach defensible conclusions. Along the way, they learn how to use AI effectively for summarization, triage, enrichment, drafting, detection support, and automation without confusing generated output for evidence.

Students will work through realistic SOC workflows that connect alerts to action: collecting evidence, enriching context, building hypotheses, reducing false positives, writing and testing detections, documenting investigations, and deciding when to escalate. The course also covers agentic AI concepts, tool use, automation design, prompt-injection risk, approval gates, audit trails, and analyst sustainability.

By the end of the course, students will be better prepared to operate in modern SOCs where human analysts, security platforms, automation, and AI-enabled systems work together. The focus is practical: use the tools, validate the evidence, make better decisions, and help the organization reduce risk.

What You’ll Learn

  • Define SOC mission and scope so analysts focus on what matters most
  • Use threat intel to prioritize threats and sharpen triage decisions
  • Analyze network, endpoint, email, and file evidence across the SOC toolset
  • Separate observed facts from assumptions and AI-generated inferences
  • Apply structured methods like ACH to reduce bias in investigations
  • Write, test, and document detections using Sigma and YARA concepts
  • Evaluate agentic AI workflows for prompt-injection risk and approval gates

Business Takeaways

  • Sharper triage and evidence review mean analysts spend more time on real threats
  • Get more value from SIEM, EDR/XDR, threat intel, and automation working together
  • Speed up investigations with AI while preserving evidence and human decisions
  • Turn investigation findings into tested, documented detections with Sigma/YARA
  • Adopt AI with real controls: approval gates, audit trails, and least privilege
  • Reduce analyst toil and burnout with better handoffs and documentation
  • Build a team ready to oversee agentic AI and make defensible SOC decisions

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC450: AI-Enabled Security Operations: Hands-on Investigation, Detection, and Automation.

Section 1Building the AI-Enabled SOC: Mission, Intelligence, Tools, and Workflow

Start by defining the SOC’s mission and toolset, then learn how CTI sharpens prioritization and how to build a threat-informed defense. You’ll also get hands-on with AI fundamentals, from safe prompting to verifying AI-generated output before it becomes part of a case.

Topics covered

  • Course Framing, SOC Mission, and Scope
  • SOC Tool Landscape
  • CTI for Prioritization and Context
  • Building a Threat-Informed Defense
  • AI Basics, Usage, and the Analyst Workflow

Labs

  • From Alert to Case: Using SOC Tools
  • From Threat Reports to SOC Priorities
  • AI Prompting for SOC Analysts
  • AI Output Verification

Section 2Network Evidence and Agentic Enrichment: Protocols, OPSEC, and Tool Use

Build the network evidence skills every SOC analyst needs: DNS, HTTP, and TLS traffic analysis, plus OPSEC considerations that keep your own investigation from creating risk. You'll also start applying agentic AI concepts, tool use, and iteration to enrich alerts faster.

Topics covered

  • Network Protocol Fundamentals: DNS, HTTPS, TLS, and more
  • OPSEC
  • Alert Enrichment and Evidence Quality
  • Agentic AI Concepts: Planning, Tool Use, and Iteration
  • Tools and Tool Use

Labs

  • DNS and HTTP/1.1 Analysis
  • HTTP/2, HTTP/3, and TLS Traffic Analysis
  • OPSEC for Defenders
  • Manual and Agentic Alert Enrichment

Section 3From Telemetry to Investigation: Triage, Structured Analysis, and Agentic Automation

Move from raw telemetry to real investigations. Collect and interpret host, endpoint, and cloud evidence, apply structured analytical techniques to reduce bias, and use automation and agent-based workflows to triage alerts and build phishing-triage pipelines.

Topics covered

  • Host, Endpoint, and Cloud Telemetry Collection and Formats
  • Triage and Investigation Mindset, Process, and Techniques
  • Structured Analytical Techniques
  • Automation, Agent Configuration, Context, and Usage
  • Alert Triage and Event Collection

Labs

  • Identity Telemetry Analysis: Validating Cross-Platform Login Activity
  • AI-Enabled Analysis Tools and Methods
  • Building an AI-Powered Phishing-Triage Workflow
  • Agent-Controlled Automation

Section 4From Phishing to Detection: Email, Malware Analysis, YARA-X, and Sigma

Go deep on phishing and malware: analyze email headers, dissect weaponized file types, and learn malware analysis foundations. Then translate what you find into tested detection logic using YARA-X for files and Sigma for log-based detections.

Topics covered

  • Malicious Email Prevention and Spoofing
  • File and Malware Analysis Foundations and Weaponized File Types
  • Detection Engineering Concepts
  • File and Malware Detection with YARA-X
  • Log-Based Detection with Sigma

Labs

  • Analyzing Phishing Email Headers
  • Dissecting Common Malware File Types
  • File-Based Detection with YARA-X
  • Log-Based Detection Engineering with Sigma

Section 5Operating the AI-Enabled SOC: Risk, Judgment, and Sustainable Performance

Close out by examining AI trust and risk, the analyst's evolving role in AI-enabled SOCs, and practices that reduce burnout and support career growth. The course ends with a capstone incident that pulls every skill from the course together.

Topics covered

  • AI Trust and Risk
  • Analyst Role in AI-Enabled SOCs
  • Burnout Reduction for Security Operations Teams
  • Career Growth
  • SEC450 Capstone Exercise

Labs

  • AI-Assisted Workflow Risk Assessment
  • Build a Custom SOC Utility with AI
  • SEC450 Capstone: The MoneyMatrix Incident

Things You Need To Know

Important! Bring your own system configured according to these instructions. 

A properly configured system is required for each student participating in this course. Before coming to class, carefully read and follow these instructions exactly.

You can use any 64-bit version of Windows, macOS, or Linux as your core operating system that also can install and run VMware virtualization products. While you also must have 8 GB of RAM or higher for the VM to function properly in the class, 16GB is highly recommended if you wish to use the full functionality of the virtual machine.

It is critical that your CPU and operating system support 64-bit so that our 64-bit guest virtual machine will run on your laptop.

In addition to having 64-bit capable hardware, AMD-V, Intel VT-x, or the equivalent must be enabled in BIOS/UEFI.

Please download and install the most recent version of VMware Workstation, VMware Fusion, or VMware Workstation Player (VirtualBox and other virtualization platforms are not supported) on your system prior to the beginning of class. 

Mandatory System Hardware Requirements

  • CPU: 64-bit 2.0+ GHz processor or higher-based system is mandatory for this class (Important - Please Read: a 64-bit system processor is mandatory)
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS/UEFI: VT-x, AMD-V, or the equivalent must be enabled in the BIOS/UEFI
  • RAM: 8 GB (gigabytes) of RAM or higher is mandatory for this class, 16GB is very highly recommended for full (Important - Please Read: 8 GB of RAM or higher is mandatory)
  • Disk: 80 gigabytes of free disk space for the course virtual machine

Connectivity

  • Wireless Internet connectivity
  • USB-A ports or an adapter to use a USB-A thumb drive (version 3.0 compatibility highly recommended)

Software

  • VMware Workstation, Workstation Player, or Fusion. 
  • The Linux virtual machine will be provided in class via USB thumb drive.

Configuration

  • Please verify before coming to class that you have the administrative permissions required to transfer a virtual machine from a USB drive to your hard disk and start it. Also verify that Windows Device Guard, DLP, or other host-based protections will not interfere with the USB transfer or VM startup. (This is a common issue with company-built PCs, so if you intend to bring a corporate laptop, please test this before the event.)

If you have questions about the laptop specifications, please contact customer service

This course is designed for security professionals who work in or support security operations: SOC analysts and intrusion detection analysts; cyber defense analysts moving beyond basic alert handling; incident handlers building stronger triage, evidence, and documentation skills; detection engineers who want more operational context for rule development and tuning; security engineers supporting SIEM, EDR/XDR, SOAR, case management, and AI-enabled SOC tooling; threat intelligence analysts connecting CTI more directly to SOC prioritization; and SOC leads or managers who need to understand how AI, automation, and analyst process fit together.

The GIAC Security Operations Certified (GSOC) certification validates a practitioner's ability to defend an enterprise using essential blue team incident response tools and techniques. GSOC-certified professionals are well-versed in the technical knowledge and key concepts needed to run a security operations center (SOC).

  • SOC monitoring and incident response using incident management systems, threat intelligence platforms, and SIEMs
  • Analysis and defense against the most common enterprise-targeted attacks
  • Designing, automating, and enriching security operations to increase efficiency

More Certification Details

  • Course books
  • Custom distribution of the Linux Virtual Machine containing a pre-build simulated SOC environment
  • MP3 audio files of complete course lectures

This course assumes foundational knowledge equivalent to entry-level SOC analyst requirements. You should have a basic understanding of TCP/IP networking and general operating system concepts across Windows and Linux environments. Some familiarity with core security principles and common attack types is helpful, though we'll build on these concepts throughout the course.

The course is designed for current SOC analysts looking to advance their skills and professionals actively pursuing SOC analyst roles. If you're comfortable with basic networking concepts, can navigate command-line interfaces, and understand fundamental security terminology, you're ready for the techniques we'll cover. We'll teach you the specific tools, logging mechanisms, and advanced techniques; you just need the foundational knowledge to build on.

This is a practical SOC analyst course for the AI era. It does not treat AI as a replacement for analysts, and it does not teach AI as a standalone novelty. Instead, it teaches students how modern SOC work actually gets done: by combining mission clarity, evidence discipline, threat-informed prioritization, detection engineering, automation, AI-assisted workflows, and human judgment. 

SEC450 is designed to build job-ready skills for those entering or advancing in defensive cybersecurity roles.

Key Career Benefits

  • Hands-On SOC Skills: Learn log analysis, SIEM operations, and incident triage, the core skills needed for Tier 1 and Tier 2 SOC analyst roles.
  • Career Acceleration: Ideal for transitioning into cyber defense or strengthening early blue team experience.
  • GIAC Certification (GSOC): Earn an industry-recognized credential that validates your ability to operate in real-world security environments.
  • Professional Network: Connect with instructors and peers through SANS's global cybersecurity community.
  • Path to Advancement: Builds a foundation for higher-level courses like SEC511 (Continuous Monitoring) and SEC555 (Detection Engineering).

Bottom Line

SEC450 equips you with the practical knowledge, certification, and connections to launch or accelerate a career in blue team cybersecurity.

Relevant Job Roles

Protection

SCyWF: Protection And Defense

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Explore learning path

Defense

SCyWF: Protection And Defense

This role uses monitoring and analysis tools to identify and analyze events and to detect incidents. Find the SANS courses that map to the Defense SCyWF Work Role.

Explore learning path

Intrusion Detection/SOC Analysts

Digital Forensics and Incident Response

Analyze network and endpoint data to swiftly detect threats, conduct forensic investigations, and proactively hunt adversaries across diverse platforms including cloud, mobile, and enterprise systems.

Explore learning path

Blue Teamer - All Around Defender

Cyber Defense

This job, which may have varying titles depending on the organization, is often characterized by the breadth of tasks and knowledge required. The all-around defender and Blue Teamer is the person who may be a primary security contact for a small organization, and must deal with engineering and architecture, incident triage and response, security tool administration and more.

Explore learning path

SOC Manager

Cybersecurity Leadership

Security Operations Center (SOC) managers bridge the gap between business processes and the highly technical work that goes on in the SOC. They direct SOC operations and are responsible for hiring and training, creating and executing cybersecurity strategy, and leading the company’s response to major security threats.

Explore learning path

Information Security (SCTY)

Skills Framework for the Information Age

Implementation and oversight of security measures to protect organisational data, systems, and operations. Responsibilities include risk assessments, policy enforcement, and compliance with regulatory standards.

Explore learning path

Security Operations (SCAD)

Skills Framework for the Information Age

Monitoring and response to security incidents in live environments. Analysts detect anomalies, triage alerts, and coordinate defensive actions to maintain organisational security posture.

Explore learning path

Infrastructure Support (OPM 521)

NICE: Protection and Defense

Responsible for testing, implementing, deploying, maintaining, and administering infrastructure hardware and software for cybersecurity.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxesBuy now for access on Oct 14. Use code Presale10 for 10% off course price!
    Registration Options
  • Location & instructor

    SANS Virginia Beach 2026

    Virginia Beach, VA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam October 2026

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Safari 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London December 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £6,715 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Rockville 2027

    Rockville, MD, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online Europe April 2027

    Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
Showing 9 of 9

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources