Group Purchasing
Group Purchasing
AI SKILLS

SEC450: SOC Analyst Training – Applied Skills for Cyber Defense Operations

SEC450Cyber Defense, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
John Hubbard
John Hubbard
SEC450: Blue Team Fundamentals: Security Operations and Analysis
Course authored by:
John Hubbard
John Hubbard
  • GIAC Security Operations Certified (GSOC)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 22 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

This course delivers essential training for Security Operations Center (SOC) analysts, equipping you with the skills to detect, stop cyberattacks, and safeguard your organization’s data and systems.

Course Overview

SEC450 is a SOC Analyst training course ideal for those working in cyber defense operations or building and improving a SOC. It offers six days of training, hands-on labs, and a Capstone competition, covering the mission, mindset, and techniques needed for modern cyber defense. The course, paired with the GIAC GSOC certification, provides essential skills for detecting and halting advanced cyberattacks, making it the gold standard in security operations training.

If you're looking for the gold standard in SOC analyst training, you've found it. SANS SEC450 transforms reactive analysts into expert threat hunters who catch sophisticated attacks others miss. Unlike other courses, SEC450 has the depth to and hands-on content to teach you to think and investigate like an elite analyst using 22 hands-on labs using in a realistic SOC environment. Check out the syllabus below for details or jump to the free demo available by clicking the "Course Demo" button!

Designed for SOC analysts from organizations of all sizes, SEC450 will get you hands-on with the tools and techniques required to stop advanced cyberattacks! Whether you are a part of a full SOC in a large organization, a small security ops group, or an MSSP responsible for protecting customers, SEC450 will teach you and your team the critical skills for understanding how to defend a modern organization, including how to get the most out of the new capabilities provided by generative AI.

Transform overwhelmed analysts into confident threat hunters who identify compromise before it becomes a breach. Master advanced network traffic analysis, malware investigation, and the structured hunting techniques that separate elite defenders from those drowning in alerts. Learn detection engineering that actually works and investigation methods that catch sophisticated attacks automated tools miss.

SEC450 covers the complete spectrum from strategic SOC operations and threat intelligence to hands-on packet analysis and malware dissection. You'll work with fully integrated set of SOC tools configured exactly how they operate in production environments. Every technique directly translates to your workplace because it's based on real SOC operations at enterprise scale. The course culminates in an intensive capture-the-flag competition where you'll prove you can apply these advanced techniques under pressure - exactly what real SOC operations demand.

Hands-On SOC Analyst Training

This course delivers 22 hands-on labs that put you directly into realistic SOC scenarios to get interactively learning and using the real tools of the trade. Your virtual environment mirrors a real SOC with integrated SIEM, threat intelligence platforms, incident management systems, SOAR tools, full packet capture tools, and a toolkit of command-line tools that analysts use daily. Everything is pre-configured and ready to go so you can jump in to the workflow and gain skills that transfer immediately to your workplace.

You'll tackle real-world challenges through practical exercises: analyzing HTTP, DNS, and email-based attacks, hunting for post-exploitation activity, and performing high-quality investigations under realistic constraints. The labs teach you to identify high-risk alerts quickly, understand how logs flow through detection pipelines, and get hands-on with tools to create detection rules for files and logs that actually work in production. By course end, you'll have hands-on experience with the integrated tool workflows that separate effective SOCs from those drowning in alert fatigue - experience you can apply the moment you return to your own environment.

SEC450 takes the approach of not just teaching what to do, but also why these techniques work. Unlike shorter security analyst training courses, SEC450 has the time to cover the deeper reasoning and principles behind successful cyber defense strategies, ensuring students can apply the concepts beyond the class material and bring a successful defensive mindset back to their teams and organizations. Don't just take our word for it, ask any of our thousands of course alumni and GIAC GSOC certified analysts!

Author Statement

"As someone who has done years of SOC consulting and held every position from entry-level SOC analyst to SOC manager at a 100,000-employee company, I thoroughly understand the struggle of careers in security operations. While there is a seemingly infinite amount of information to learn, there are central concepts that, when explained systematically, can significantly shorten the time required to become a highly effective member of your SOC team.

SEC450 is the course that I wish I had when I got started and will pass those key pieces of SOC analyst knowledge on to you to take back to your team, giving you both the high- and low-level concepts required to propel your career in cyber defense. It's packed with both the technical concepts that all SOC analysts must understand to stop high-impact cyber-attacks, as well as the thought processes behind them to encourage a deep understanding of why our approach to cyber defense works.

I've worked hard to distill lessons learned over years working in, and with, SOC teams worldwide, so you can bypass the common struggles, misunderstandings, and frustration so common in SOC analyst teams and roles. Not only does SEC450 keep you and your team defending against world-class attackers, but complements that knowledge with what it takes to do it all in a sustainable and burnout-free way. I truly love cyber defense work, and want you and your team to as well, so I hope to see you in SEC450 so we can help you build a wildly successful, life-long career on the blue team!"

- John Hubbard

What You’ll Learn

  • Security Data Collection – How to make the most of security telemetry including endpoint, network, application, and cloud-based data
  • Automation – How to identify the best opportunities to make your team more efficient, utilizing scripts, SOAR, and AI agents
  • Efficient Security Process – How to keep your security operations tempo on track with in-depth discussions on what a SOC or security operations team should be doing at every step from security monitoring to detection, triage, analysis, and beyond
  • Quality Triage and Analysis – How to quickly identify the separate typical commodity attack alerts from high-risk, high-impact advanced attacks, and how to do careful, thorough, and cognitive-bias free security incident analysis
  • False Positive Reduction – Detailed explanations, processes, and techniques to reduce false positives to a minimum
  • SOC Tools – Hands-on exercises demonstrating how to collect, organize, and use relevant threat data in a Threat Intelligence Platform (TIP); Principles of success for endpoint security data collection whether you use a SIEM, EDR, NDR, or XDR; how to quickly and accurately triage security incidents; crafting generative AI-powered automation workflows for common SOC activities; and how to best use case management systems to effectively analyze, document, track, and extract critical metrics from your security incidents
  • Burnout and Turnover Reduction – Informed with both scientific research and years of personal experience, this class teaches what causes cyber security analyst burnout and how you and your team can avoid it by understanding the causes and factors that lead to burnout. This class will help you build a long-term sustainable cyber defense career so you and your team can deliver the best every day!

Business Takeaways

  • Stop missing real threats - Your analysts will master advanced detection techniques that catch sophisticated attacks others miss, including network-based hunting, malware analysis, and structured investigation methods that quickly and accurately identify compromise
  • Eliminate alert fatigue - Learn proven detection engineering and tuning strategies that dramatically reduce false positives while maintaining security coverage, allowing your team to focus on actual threats
  • Maximize your security technology investment - Get full value from your SIEM, XDR, EDR, and threat intelligence platforms through proper integration, advanced query techniques, and workflow optimization that most organizations never achieve
  • Accelerate incident response - Implement structured triage processes, quality investigation frameworks, and AI-powered automation that cut response times and improve accuracy under pressure
  • Build sustainable operations - Develop your team's expertise in the advanced skills that prevent burnout, reduce turnover, and create the high-performing SOC analysts every organization struggles to find and retain

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC450: SOC Analyst Training – Applied Skills for Cyber Defense Operations.

Section 1Blue Team Tools and Operations

Section 1 lays the groundwork for SOC analysts, covering threat models, analyst workflows, and key tools like SIEM and SOAR. It closes with how to apply generative AI in security operations, from improving documentation and analysis to understanding AI-driven threats and tools—preparing you for the future of AI in cyber defense.

Topics covered

  • Foundations of Security Operations
  • Cyber Threat Intelligence (CTI) and Building a Threat-Informed Defense
  • SOC Data and Tools
  • Generative AI for the SOC

Labs

  • Threat Intelligence Platforms (TIPs) for SOC Analysts
  • Using a SIEM for Log Analysis
  • Case Management Systems – Playbooks and Workflow Design
  • The AI-Powered SOC – Prompting, Investigating, and Coding with LLMs

Overview

Section 1 establishes the strategic foundation every SOC analyst needs to operate effectively in modern security operations. You'll start by understanding what SOCs are actually trying to accomplish, how to analyze your organization's threat model, and why building threat-informed defenses matters more than deploying generic security controls. We'll cover the analyst mindset, essential workflows, and how SOC information management tools fit together - from incident management systems and threat intelligence platforms to SIEMs, SOAR tools, and the complete technology stack that powers effective cyber defense.

The section concludes with a comprehensive look at generative AI in security operations. You'll identify practical opportunities for AI integration, understand emerging technologies like MCP and AI agents, and explore specific use cases for SOC workflows. We'll cover how AI can improve documentation, research, and analysis while also examining AI-based threats and defensive considerations. By the end, you'll understand how to position yourself and your SOC for the AI-powered future of cybersecurity.

Full Lab Details

  • Threat Intelligence Platforms for SOC Analysts
  • Using a SIEM for Log Analysis
  • Case Management Systems - Playbooks and Workflow Design
  • The AI-Powered SOC - Prompting, Investigating, and Coding with LLMs

Full Topic Details

  • Foundations of security operations
    • What is a SOC trying to achieve
    • How does a SOC achieve their goal?
    • Resources needed for a successful SOC
  • Cyber Threat Intelligence (CTI) and Building a Threat-Informed Defense
    • CTI for SOC Analysts
    • Threat intelligence platforms
    • Building a Threat-Informed Defense
  • SOC Data and Tools
    • Evidence Data and Tools (SIEM, XDR, EDR, NDR, etc.)
    • Process and Investigation Data and Tools (Case management tools, SOAR, playbooks and use cases)
    • Contextual Data and Tools (Threat intelligence platforms, vulnerability data, identity information, asset inventories, etc.)
  • Generative AI for the SOC
    • Identifying opportunities and best practice for when to use generative AI
    • MCP, AI Agents, and A2A
    • Generative AI use cases for the SOC
    • Improving workflow, documentation, and research with AI
    • AI-based threats and dangers
    • Moving toward the AI-powered SOC of the future

Section 2Understanding Your Network

Section 2 dives into network-based threat hunting. Learn to use routers, firewalls, flow logs, and full packet capture to track attacker activity. You'll analyze DNS, HTTP, and TLS traffic, spot encrypted threats without decryption, and explore post-exploitation protocols—building skills to detect threats others overlook.

Topics covered

  • Network Visibility & Traffic Analysis
  • DNS Monitoring & Threat Detection
  • HTTP Traffic Dissection
  • Encrypted Traffic Analysis
  • Post-Exploitation Protocols

Labs

  • Monitoring DNS Requests, Traffic, and Analysis
  • Analyzing Malicious DNS
  • Wireshark Workflow and HTTP Analysis
  • Decoding and Analyzing HTTP/2 and HTTP/3 Traffic
  • Analyzing TLS Traffic without Decryption

Overview

Section 2 is introduced with a deep dive into network-based threat hunting, where you'll master the art of catching attackers through traffic analysis. This session begins with building a solid foundation in network architecture and security monitoring, teaching you how routers, switches, and firewalls all can be used for maximum visibility and monitoring traffic flow patterns. You'll then master the critical tools of the trade from flow logs and metadata to full packet capture, learning how to use each format and how to extract maximum intelligence from network data.

The core part of this section shows how to dissect the protocols attackers love to abuse. You'll become a DNS expert, understanding normal usage patterns and critical record types before diving into DNS-based attacks like tunneling and domain generation algorithms. We'll crack open HTTP traffic analysis, from method and header inspection to file extraction, then explore cutting-edge HTTP/2 and HTTP/3 dissection techniques. You'll learn to detect suspicious encrypted traffic even without decryption using TLS fingerprinting, certificate inspection, and understanding how TLS 1.3 and ECH are changing the game for attackers and defenders. Finally, we'll explore the protocols attackers use post-exploitation, including remote administration tools that often hide in plain sight. By day's end, you'll think like a network hunting expert, capable of spotting the subtle signs of compromise that others miss.

Full Lab Details

  • Monitoring DNS Requests, Traffic, and Analysis
  • Analyzing Malicious DNS
  • Wireshark Workflow and HTTP Analysis
  • Decoding and Analyzing HTTP/2 and HTTP/3 Traffic
  • Analyzing TLS Traffic without Decryption

Full Topic Details

  • Network Architecture and Security Monitoring
    • Routers, Switches, and Firewalls for Visibility
    • Security Zones and Traffic Flow
  • Traffic Capture Formats and Analysis Tools
    • Options for Traffic Capture
    • Flow Logs, Metadata, and Full Packet Capture
  • Deep Dive on DNS
    • Understanding Normal Usage Patterns
    • Important Record Types for Security Monitoring
    • DNS over HTTPS (DoH) Implications for Security Teams
  • DNS analysis and attacks
    • Enriching DNS Logs for Threat Detection
    • DNS-Based Attacker Techniques (DNS Tunneling, Domain Generation Algorithms and More)
  • HTTP Methods and Header Analysis
    • HTTP Methods and Key Header Data for Monitoring
    • File Extraction from Captured HTTP Transactions
  • HTTP-Based Threats, Attacks, and Analysis
    • Automated and Manual HTTP Analysis Methods
    • Investigating Suspicious HTTP Transactions
  • HTTP/2 & HTTP/3
    • How HTTP/2 Works, and How to Dissect It
    • How HTTP/3 Works, and How to Dissect It
  • Detection Suspicious Traffic with and without Decryption
    • TLS Interception and Decryption Methods
    • HTTPS and Certificate inspection
    • TLS Fingerprinting
    • TLS1.3 and ECH Implications for Security Monitoring
  • Common Protocols for Post-Exploitation
    • Remote Administration Protocols of Interest
    • Catching Lateral Movement

Section 3Understanding Endpoints, Logs, and Files

Section 3 builds your skills in log analysis and malware fundamentals. You’ll learn to craft SIEM queries, visualize data, and spot attacker activity across Windows, Linux, and cloud logs. Then, dive into malware handling, static analysis, IOC extraction, and sandboxing to uncover threats hiding in weaponized files and complex data.

Topics covered

  • Deep Dive on SIEM for Threat Detection
  • How Windows and Linux Logging Works
  • Key Log Events for Threat Detection and How to Interpret Them
  • Cloud Logging
  • Malware Analysis Fundamentals

Labs

  • Building SIEM Visualizations and Dashboards
  • Threat Hunting with a SIEM
  • Suspicious File Triage, Static Analysis, and Malware Sandboxes
  • Reverse Engineering Common Malware File Types

Overview

The first half of section 3 focuses on transforming you into a log analysis expert, teaching you to extract meaningful threat intelligence from the massive volumes of data flowing through modern security environments. You'll master SIEM usage including precise search query crafting and visualization creation that turns raw data into actionable insights. We'll cover Windows and Linux logging mechanisms, critical event types that reveal attacker activity, and comprehensive cloud logging across AWS CloudTrail, Azure Activity Logs, Entra ID, and Microsoft 365's Unified Audit Log.

The second half of the section focuses on malware analysis fundamentals every SOC analyst needs. You'll learn safe file handling procedures, static analysis techniques, IOC extraction, and how to leverage automated sandboxes effectively. We'll dissect commonly weaponized file types and show you how to extract intelligence that strengthens your organization's defenses. By the end, you'll confidently navigate complex log data and suspicious files to uncover the threats others miss.

Full Lab Details

  • Building SIEM Visualizations and Dashboards
  • Threat Hunting with a SIEM
  • Suspicious File Triage, Static Analysis, and Malware Sandboxes
  • Reverse Engineering Common Malware File Types

Full Topic Details

  • Deep Dive on SIEM for Threat Detection
    • Key SIEM Deployment Considerations
    • Understanding and Crafting Effective SIEM Search Queries
    • SIEM Visualizations and Dashboard Creation
  • How Windows and Linux Logging Works
    • Audit Logs and Channels of Interest
  • Key Log Events for Threat Detection and How to Interpret Them
  • Cloud Logging
    • AWS and CloudTrail
    • Azure Activity Logs
    • Entra ID Audit Logs
    • Microsoft 365 and the Unified Audit Log
    • Key Event Types for Threat Detection
  • Malware Analysis Fundamentals
    • Handling and Moving Suspicious Files
    • Static Analysis and File Identification
    • Identifying Malicious Files and Basic IOC Extraction
    • How to use Automated Malware Sandboxes
    • Commonly Weaponized File Types, and How to Dissect Them

Section 4Triage and Analysis

Section 4 builds expertise in phishing investigations and structured analysis. Learn to detect spoofed emails, block malicious links, and investigate BEC and MFA bypasses. Then sharpen your triage and decision-making with OPSEC best practices and structured techniques to reduce bias, prioritize alerts, and analyze threats with clarity under pressure.

Topics covered

  • Phishing Prevention
  • How to Investigate Common Phishing Techniques
  • Alert Triage and Prioritization
  • Structured Analysis Techniques
  • Operational Security (OPSEC) for SOC Analysts

Labs

  • Analyzing Phishing Email Headers and Identifying Spoofed Email
  • Dissecting Modern Malicious Email Attachments
  • Applied Alert Triage & Prioritization
  • Applying Structured Analysis Techniques for High Quality Investigation

Overview

Section 4 focuses on two critical SOC skills: mastering phishing investigations and developing structured analysis techniques that separate expert analysts from beginners. The first half covers comprehensive phishing defense, from blocking suspicious URLs and attachments to identifying spoofed emails and stopping sophisticated BEC scams. You'll then investigate common phishing techniques, learning how attackers manipulate users into clicking, where they host malicious content, how they evade automated scanners, and the latest MFA bypass methods that are fooling even security-aware users.

The second half transforms your analysis approach through structured techniques and operational security. You'll master alert triage and prioritization, learning the essential information needed for accurate decisions and designing workflows that handle high-volume environments effectively. We'll cover operational security for SOC analysts—investigating threats without alerting attackers to your activities, avoiding common OPSEC mistakes, and anonymizing investigations. Finally, you'll learn structured analytical techniques that help you avoid cognitive biases, understand which evidence truly matters, and develop workflows that consistently produce high-quality analysis under pressure.

Full Lab Details

  • Analyzing Phishing Email Headers and Identifying Spoofed Email
  • Dissecting Modern Malicious Email Attachments
  • Applied Alert Triage & Prioritization
  • Applying Structured Analysis Techniques for High Quality Investigation

Full Topic Details

  • Phishing Prevention
    • Blocking Suspicious URLs and Attachments
    • Identifying Spoofed Email
    • Stopping Social Engineering and Business Email Compromise (BEC) Scams
  • How To Investigate Common Phishing Techniques
    • How Attackers Get Users to Click
    • Phishing Hosting
    • Hiding Attackers Hide Phishing Links from Automated Scanners
    • MFA Bypass Techniques and How to Spot Them
    • Business Email Compromise (BEC) Scam Types
  • Alert Triage and Prioritization
    • The Information Required for Accurate Alert Triage
    • Goals and Mindset for Triage
    • Alert and Triage Workflow Design
  • Structured Analysis Techniques
    • Avoiding Common Analysis Errors
    • Knowing Which Evidence Data Does and Doesn’t Matter
    • Workflow for High-Quality Analysis
  • Operational Security (OPSEC) for SOC Analysts
    • Investigating Attack Attempts without Tipping Your Hand to Attackers
    • Common OPSEC Mistakes, and how to Avoid Them
    • Anonymizing Your Investigations

Section 5Continuous Improvement, Analytics, and Automation

Section 5 takes you from analyst to detection engineer. Learn to craft high-fidelity detections with tools like YARA-X and Sigma, reduce false positives, and tune alerts effectively. Explore where automation helps or hurts, assess investigation quality, and build sustainable skills to grow your cybersecurity career without burning out.

Topics covered

  • Detection Engineering
  • Alert Tuning and False Positive Reduction
  • Automation and Orchestration
  • Investigation Quality
  • How to Avoid Burnout for SOC Analysts

Labs

  • File-Based Detection with YARA-X
  • Log-Based Detection with Sigma
  • Alert Tuning and False Positive Reduction
  • Integrating generative AI into SOC Automation
  • Collecting and Documenting Incident Information for Effective Incident Reporting

Overview

Section 5 elevates you from reactive analyst to proactive detection engineer and sets you up for long-term career success. You'll start with detection engineering fundamentals, understanding why high-fidelity detections are so challenging to create and mastering different signature types. We'll dive into practical tools like YARA-X for malware detection and Sigma for log-based rules, giving you hands-on experience building detections that actually work in production environments.

The section then tackles the critical challenge of alert tuning and false positive reduction. You'll learn how to determine appropriate alert volumes, understand why detections perform poorly in practice, and implement proven strategies to reduce noise while maintaining security coverage. We'll explore automation and orchestration, showing you when automation helps versus when it creates new problems, plus practical use cases that genuinely improve SOC efficiency. Finally, you'll develop skills for investigation quality assessment, learn structured review techniques, and get essential guidance on avoiding burnout and advancing your cybersecurity career sustainably.

Full Lab Details

  • File-Based Detection with YARA-X
  • Log-Based Detection with Sigma
  • Alert Tuning and False Positive Reduction
  • Integrating generative AI into SOC Automation
  • Collecting and Documenting Incident Information for Effective Incident Reporting

Full Topic Details

  • Detection Engineering
    • Why Is It So Difficult To Write a High-Fidelity Detection?
    • Signature Types
    • YARA-X for Malware File Detection
    • Sigma for Log-Based Detection
  • Alert Tuning and False Positive Reduction
    • How Many Alerts Should You Create?
    • Why Alerts Perform Poorly
    • Strategies to Reduce Alert Volume
  • Automation and Orchestration
    • When and When Not To Use Automation
    • Automation Use Cases
  • Investigation Quality
    • What Does a High-Quality Investigation Look Like?
    • How Can We Measure Ourselves and Our Team’s Work?
    • Structured Review Techniques
  • How to Avoid Burnout For SOC Analysts
    • The Factors that Increase Engagement at Work
    • Good and Bad Stress on the Job
  • Skill and Career Development Advice

Section 6Capstone: Defend the Flag

The course ends with a high-stakes, team-based capture the flag challenge. Using real network data in a simulated attack, you’ll race to detect and analyze threats across multiple scenarios. It’s a full day of hands-on problem solving that tests your ability to perform advanced threat hunting under real-world pressure.

Overview

The course culminates in an intense, team-based capture the flag competition that puts everything you've learned to the test. Working with real network data and logs from a simulated environment under active attack, you'll race against other teams to detect and identify sophisticated threats across multiple challenge categories. This isn't just review—it's a full day of high-stakes problem solving that proves you can apply advanced threat hunting and analysis techniques under pressure, just like you'll face in real SOC operations.

Things You Need To Know

Important! Bring your own system configured according to these instructions. 

A properly configured system is required for each student participating in this course. Before coming to class, carefully read and follow these instructions exactly.

You can use any 64-bit version of Windows, macOS, or Linux as your core operating system that also can install and run VMware virtualization products. While you also must have 8 GB of RAM or higher for the VM to function properly in the class, 16GB is highly recommended if you wish to use the full functionality of the virtual machine.

It is critical that your CPU and operating system support 64-bit so that our 64-bit guest virtual machine will run on your laptop.

In addition to having 64-bit capable hardware, AMD-V, Intel VT-x, or the equivalent must be enabled in BIOS/UEFI.

Please download and install the most recent version of VMware Workstation, VMware Fusion, or VMware Workstation Player (VirtualBox and other virtualization platforms are not supported) on your system prior to the beginning of class. 

Mandatory System Hardware Requirements

  • CPU: 64-bit 2.0+ GHz processor or higher-based system is mandatory for this class (Important - Please Read: a 64-bit system processor is mandatory)
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS/UEFI: VT-x, AMD-V, or the equivalent must be enabled in the BIOS/UEFI
  • RAM: 8 GB (gigabytes) of RAM or higher is mandatory for this class, 16GB is very highly recommended for full (Important - Please Read: 8 GB of RAM or higher is mandatory)
  • Disk: 80 gigabytes of free disk space for the course virtual machine

Connectivity

  • Wireless Internet connectivity
  • USB-A ports or an adapter to use a USB-A thumb drive (version 3.0 compatibility highly recommended)

Software

  • VMware Workstation, Workstation Player, or Fusion. 
  • The Linux virtual machine will be provided in class via USB thumb drive.

Configuration

  • Please verify before coming to class that you have the administrative permissions required to transfer a virtual machine from a USB drive to your hard disk and start it. Also verify that Windows Device Guard, DLP, or other host-based protections will not interfere with the USB transfer or VM startup. (This is a common issue with company-built PCs, so if you intend to bring a corporate laptop, please test this before the event.)

If you have questions about the laptop specifications, please contact customer service

SEC450 training is intended for those who are early in their career or new to working in a SOC environment, including:

  • Security Analysts
  • Incident Investigators
  • Security Engineers and Architects
  • Technical Security Managers
  • SOC Managers looking to gain additional technical perspective on how to improve analysis quality, reduce turnover, and run an efficient SOC
  • Anyone looking to start their career on the blue team

The GIAC Security Operations Certified (GSOC) certification validates a practitioner's ability to defend an enterprise using essential blue team incident response tools and techniques. GSOC-certified professionals are well-versed in the technical knowledge and key concepts needed to run a security operations center (SOC).

  • SOC monitoring and incident response using incident management systems, threat intelligence platforms, and SIEMs
  • Analysis and defense against the most common enterprise-targeted attacks
  • Designing, automating, and enriching security operations to increase efficiency

More Certification Details

  • Course books
  • Custom distribution of the Linux Virtual Machine containing a pre-build simulated SOC environment
  • MP3 audio files of complete course lectures

This course assumes foundational knowledge equivalent to entry-level SOC analyst requirements. You should have a basic understanding of TCP/IP networking and general operating system concepts across Windows and Linux environments. Some familiarity with core security principles and common attack types is helpful, though we'll build on these concepts throughout the course.

The course is designed for current SOC analysts looking to advance their skills and professionals actively pursuing SOC analyst roles. If you're comfortable with basic networking concepts, can navigate command-line interfaces, and understand fundamental security terminology, you're ready for the comprehensive threat hunting and analysis techniques we'll cover. We'll teach you the specific tools, logging mechanisms, and advanced techniques - you just need the foundational knowledge to build upon.

Security operations and analysis refer to the processes and practices focused on monitoring, detecting, and responding to cybersecurity threats within an organization's network. These operations are carried out by a team of security analysts who leverage various tools and techniques to ensure the integrity and safety of digital assets. Security operations aim to identify potential threats, minimize the impact of incidents, and ensure that security measures are in place to protect against cyberattacks.

Importance of security operations and analysis:

  • Threat detection -Identifies and mitigates security breaches or attacks before they cause significant damage.
  • Incident response -Enables rapid, efficient responses to cybersecurity incidents, reducing downtime.
  • Continuous monitoring -Provides 24/7 surveillance of networks, ensuring constant protection against evolving threats.
  • Risk management-Helps organizations stay compliant with regulations and manage risks effectively, protecting sensitive data.

SEC450: SOC Analyst Training – Applied Skills for Cyber Defense Operations is designed to build job-ready skills for those entering or advancing in defensive cybersecurity roles.

Key Career Benefits:

  • Hands-On SOC Skills: Learn log analysis, SIEM operations, and incident triage—core skills needed for Tier 1 and Tier 2 SOC analyst roles.
  • Career Acceleration: Ideal for transitioning into cyber defense or strengthening early blue team experience.
  • GIAC Certification (GSOC): Earn an industry-recognized credential that validates your ability to operate in real-world security environments.
  • Professional Network: Connect with instructors and peers through SANS’s global cybersecurity community.
  • Path to Advancement: Builds a foundation for higher-level courses like SEC511 (Continuous Monitoring) and SEC555 (Detection Engineering).

Bottom Line: SEC450 equips you with the practical knowledge, certification, and connections to launch or accelerate a career in blue team cybersecurity.

Relevant Job Roles

Protection

SCyWF: Protection And Defense

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Explore learning path

Defense

SCyWF: Protection And Defense

This role uses monitoring and analysis tools to identify and analyze events and to detect incidents. Find the SANS courses that map to the Defense SCyWF Work Role.

Explore learning path

Intrusion Detection/SOC Analysts

Digital Forensics and Incident Response

Analyze network and endpoint data to swiftly detect threats, conduct forensic investigations, and proactively hunt adversaries across diverse platforms including cloud, mobile, and enterprise systems.

Explore learning path

Blue Teamer - All Around Defender

Cyber Defense

This job, which may have varying titles depending on the organization, is often characterized by the breadth of tasks and knowledge required. The all-around defender and Blue Teamer is the person who may be a primary security contact for a small organization, and must deal with engineering and architecture, incident triage and response, security tool administration and more.

Explore learning path

SOC Manager

Cybersecurity Leadership

Security Operations Center (SOC) managers bridge the gap between business processes and the highly technical work that goes on in the SOC. They direct SOC operations and are responsible for hiring and training, creating and executing cybersecurity strategy, and leading the company’s response to major security threats.

Explore learning path

Information Security (SCTY)

Skills Framework for the Information Age

Implementation and oversight of security measures to protect organisational data, systems, and operations. Responsibilities include risk assessments, policy enforcement, and compliance with regulatory standards.

Explore learning path

Security Operations (SCAD)

Skills Framework for the Information Age

Monitoring and response to security incidents in live environments. Analysts detect anomalies, triage alerts, and coordinate defensive actions to maintain organisational security posture.

Explore learning path

Infrastructure Support (OPM 521)

NICE: Protection and Defense

Responsible for testing, implementing, deploying, maintaining, and administering infrastructure hardware and software for cybersecurity.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Virginia Beach 2026

    Virginia Beach, VA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam October 2026

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Safari 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,900 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London December 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £7,160 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Rockville 2027

    Rockville, MD, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 8 of 8

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources