Search logs and scope suspicious activity
Splunk First Steps · Reading Windows Logs · SPL Detective · Insider Threat Investigation
Evidence to build: Reproducible searches, event timelines, scope statements and a written escalation.
Complete SOC Investigation Programme · live with Saahil Chhabria
Build practical lab experience across individual investigations and a live team hunt. Develop a portfolio that shows how you analyse evidence, challenge conclusions and work with other analysts.
₹14,999 one-time · eight solo labs + Operation Loki
Prefer to start smaller? Foundations costs ₹1,999; the Investigation Course costs ₹5,999. Upgrade to Complete for the difference: ₹13,000 from Foundations or ₹9,000 from Investigation.
Build a portfolio across eight solo investigations, review your reports live and practise a team investigation in Operation Loki.
1. Search Splunk
Find the right index, inspect events and answer questions with evidence.
2. Read Windows logs
Interpret logons, process activity and Sysmon events.
3. Write SPL investigations
Compare hosts and users, build timelines and test a hypothesis.
4. Explain an incident
Investigate an insider threat and write findings with a containment recommendation.
5. Trace malicious execution
Connect download, process and network evidence; distinguish an attempted action from a confirmed outcome.
6. Investigate phishing-related C2
Test a beaconing hypothesis and document supporting indicators and limitations.
7. Validate an AI investigation
Check an analyst’s conclusions against source evidence and identify unsupported claims.
8. Reconstruct an APT investigation
Follow a kerberoasting attack chain and explain gaps in the evidence.
9. Investigate with a team
Own a lane in Operation Loki, hand off findings and contribute to a shared briefing.
Submit an incident report and earn a final score of 70 or more in each of the four required foundation labs, with a plan that includes the certificate.
Paid-program commitment: we help you build hiring evidence from your scored investigations and written case studies. When it is ready, and only with your permission, CymBytes will share it with relevant recruiters. This is included only in paid programs.
Build a portfolio of scored labs and your written investigation. Download your evidence pack or choose to publish a link. Instructor feedback is available through your portfolio. Recruiter sharing is consent-based and does not guarantee an interview or placement.
Bring a laptop and a stable internet connection. Ask questions during live class and use your portfolio to request feedback on a complete scored investigation. If you miss a class, contact the instructor to arrange a repeat or ask about recording availability.
Job-to-lab checklist, investigation worksheet, interview debrief prompts and one instructor-assigned follow-up exercise with portfolio feedback. Practice uses your included labs and monthly launch allowance. See the preparation guide.
Lifetime access covers the included solo practice labs; Operation Loki, where included, is instructor-led and scheduled. Live teaching covers the booked sessions; it is not an unlimited live-class subscription. Monthly launches reset on the first day of each UTC calendar month.
Start with four foundation lessons, then investigate malicious execution, phishing-related C2, AI investigation validation and an autonomous APT. The ninth live lesson reviews your reports and certificate eligibility; it is not an extra solo lab.
Operation Loki is a four-hour instructor-led team hunt at a fictional bank. Your group searches for a live intrusion across Splunk, endpoints and email, splits investigation lanes and briefs the findings. Document what you personally established and what your teammates contributed.
Bring a laptop, reliable internet and time for solo practice between lessons. Beginners can follow the foundation sequence; check the preparation for your first booked lesson before joining.
For learners who want a broader portfolio and practice explaining decisions across several investigations. The programme includes foundations and progresses into advanced exercises; completing it does not confer a professional L2 job level.
Bring a role you want to apply for. Match its responsibilities to these labs, record your evidence and identify the gaps. A curriculum match is not an employer endorsement.
Splunk First Steps · Reading Windows Logs · SPL Detective · Insider Threat Investigation
Evidence to build: Reproducible searches, event timelines, scope statements and a written escalation.
Malicious File Execution · Phishing C2 Detection
Evidence to build: Separate file presence, execution and network observations; support a conclusion and state what remains unknown.
AI Investigation Validation
Evidence to build: Check claims against original evidence and explain an unsupported inference or missed event.
Autonomous APT Investigation
Evidence to build: Connect the available evidence across a kerberoasting attack chain and identify gaps before recommending a response.
Operation Loki — four-hour team hunt
Evidence to build: Record your assigned lane, findings, handoff and contribution to the team briefing. Distinguish your own work from other analysts’ findings.
These are simulated investigations, not employment or evidence of independently running a production SOC shift. Verify each posting’s product-specific requirements, operational procedures, certifications and experience criteria. The programme does not establish proficiency in every EDR, SIEM or ticketing platform.
Save your case study in My portfolio, declare the help you used and submit for instructor feedback. Keep source events and queries with your conclusions. Publish only work you completed and can explain.
Keep your Loki contribution record in the workbook and bring it to the team debrief. It is supplementary evidence; do not attach team findings to an unrelated solo-lab score.
Download this offer’s preparation workbook →Rehearse using your own evidence. Bring a question to the booked class; debrief practice uses existing teaching time, with written feedback available through your portfolio.
After the included solo labs, request a changed question in AI Investigation Validation or Autonomous APT Investigation. Independently test a specific conclusion, identify an unsupported inference and explain what further evidence would resolve it. The instructor reviews your reasoning separately from platform scoring. During Loki’s existing debrief, explain your individual contribution and handoff.
One instructor-assigned follow-up is included. Use an included lab and your normal monthly launch allowance. Append “Follow-up assessment” to the matching case study, preserving the original. Record the assignment, date and any assistance; mark mixed if guided and independent work coexist.
This is instructor-reviewed practice, not a new automatically scored scenario or a proctored exam. Feedback covers evidence, method, uncertainty and handoff. Certificate criteria are unchanged; no extra live session is included.
Use “Practical projects” or “SOC lab investigations” and replace these placeholders with your completed work.
Completed simulated SOC investigations using Splunk, including [completed scenarios]. Validated [claim] against [evidence] and documented [finding and limitations]. In a team threat hunt, owned [lane], handed off [finding] and contributed [specific briefing content]. Evidence: [optional portfolio link].
Describe this as practical lab or project experience. Training does not count as employment, replace required years of experience, or guarantee an interview or a job. Employers decide eligibility and selection.
Loading your next available classes…
Full refund, no reason needed, any time before your third live session. Sessions count from your first scheduled session after purchase, whether or not you attend. After that, fees are non-refundable. Your checkout shows the exact deadline.
Lifetime access covers the included solo labs, with 12 launches per UTC calendar month. Operation Loki is instructor-led and scheduled; it is not an on-demand solo lab. Live teaching covers nine booked lessons and one team hunt.