Skip to content

Complete SOC Investigation Programme · live with Saahil Chhabria

Investigate the attack. Defend your reasoning. Brief the team.

Build practical lab experience across individual investigations and a live team hunt. Develop a portfolio that shows how you analyse evidence, challenge conclusions and work with other analysts.

₹14,999 one-time · eight solo labs + Operation Loki

Prefer to start smaller? Foundations costs ₹1,999; the Investigation Course costs ₹5,999. Upgrade to Complete for the difference: ₹13,000 from Foundations or ₹9,000 from Investigation.

Build a portfolio across eight solo investigations, review your reports live and practise a team investigation in Operation Loki.

Live teaching
4 evenings + 5 Saturdays + a team hunt · 9 × 60 min + 4-hour team hunt
Included labs
8 solo labs + instructor-led team hunt
Practice allowance
12 launches per calendar month
What you build
Scored lab records + an investigation portfolio
  1. 1. Search Splunk

    Find the right index, inspect events and answer questions with evidence.

  2. 2. Read Windows logs

    Interpret logons, process activity and Sysmon events.

  3. 3. Write SPL investigations

    Compare hosts and users, build timelines and test a hypothesis.

  4. 4. Explain an incident

    Investigate an insider threat and write findings with a containment recommendation.

  5. 5. Trace malicious execution

    Connect download, process and network evidence; distinguish an attempted action from a confirmed outcome.

  6. 6. Investigate phishing-related C2

    Test a beaconing hypothesis and document supporting indicators and limitations.

  7. 7. Validate an AI investigation

    Check an analyst’s conclusions against source evidence and identify unsupported claims.

  8. 8. Reconstruct an APT investigation

    Follow a kerberoasting attack chain and explain gaps in the evidence.

  9. 9. Investigate with a team

    Own a lane in Operation Loki, hand off findings and contribute to a shared briefing.

Submit an incident report and earn a final score of 70 or more in each of the four required foundation labs, with a plan that includes the certificate.

Paid-program commitment: we help you build hiring evidence from your scored investigations and written case studies. When it is ready, and only with your permission, CymBytes will share it with relevant recruiters. This is included only in paid programs.

Build a portfolio of scored labs and your written investigation. Download your evidence pack or choose to publish a link. Instructor feedback is available through your portfolio. Recruiter sharing is consent-based and does not guarantee an interview or placement.

Bring a laptop and a stable internet connection. Ask questions during live class and use your portfolio to request feedback on a complete scored investigation. If you miss a class, contact the instructor to arrange a repeat or ask about recording availability.

Job-to-lab checklist, investigation worksheet, interview debrief prompts and one instructor-assigned follow-up exercise with portfolio feedback. Practice uses your included labs and monthly launch allowance. See the preparation guide.

Lifetime access covers the included solo practice labs; Operation Loki, where included, is instructor-led and scheduled. Live teaching covers the booked sessions; it is not an unlimited live-class subscription. Monthly launches reset on the first day of each UTC calendar month.

From solo investigation to a shared incident briefing

Start with four foundation lessons, then investigate malicious execution, phishing-related C2, AI investigation validation and an autonomous APT. The ninth live lesson reviews your reports and certificate eligibility; it is not an extra solo lab.

Operation Loki is a four-hour instructor-led team hunt at a fictional bank. Your group searches for a live intrusion across Splunk, endpoints and email, splits investigation lanes and briefs the findings. Document what you personally established and what your teammates contributed.

Bring a laptop, reliable internet and time for solo practice between lessons. Beginners can follow the foundation sequence; check the preparation for your first booked lesson before joining.

Show how you investigate, challenge and collaborate

For learners who want a broader portfolio and practice explaining decisions across several investigations. The programme includes foundations and progresses into advanced exercises; completing it does not confer a professional L2 job level.

Connect the job description to your practice

Bring a role you want to apply for. Match its responsibilities to these labs, record your evidence and identify the gaps. A curriculum match is not an employer endorsement.

Search logs and scope suspicious activity

Splunk First Steps · Reading Windows Logs · SPL Detective · Insider Threat Investigation

Evidence to build: Reproducible searches, event timelines, scope statements and a written escalation.

Investigate malicious execution and C2

Malicious File Execution · Phishing C2 Detection

Evidence to build: Separate file presence, execution and network observations; support a conclusion and state what remains unknown.

Challenge an AI-generated conclusion

AI Investigation Validation

Evidence to build: Check claims against original evidence and explain an unsupported inference or missed event.

Reconstruct a multi-step intrusion

Autonomous APT Investigation

Evidence to build: Connect the available evidence across a kerberoasting attack chain and identify gaps before recommending a response.

Investigate as a team and brief findings

Operation Loki — four-hour team hunt

Evidence to build: Record your assigned lane, findings, handoff and contribution to the team briefing. Distinguish your own work from other analysts’ findings.

These are simulated investigations, not employment or evidence of independently running a production SOC shift. Verify each posting’s product-specific requirements, operational procedures, certifications and experience criteria. The programme does not establish proficiency in every EDR, SIEM or ticketing platform.

Build evidence you can discuss

  • Case studies spanning different threats, supported by your scored solo-lab records
  • An evidence-based critique of an investigation conclusion
  • An attack-chain timeline with uncertainties and response recommendations
  • A record of your personal contribution to Operation Loki and a team handoff
  • A revised portfolio following live report review and interview debrief practice

Save your case study in My portfolio, declare the help you used and submit for instructor feedback. Keep source events and queries with your conclusions. Publish only work you completed and can explain.

Keep your Loki contribution record in the workbook and bring it to the team debrief. It is supplementary evidence; do not attach team findings to an unrelated solo-lab score.

Download this offer’s preparation workbook →

Practise the interview follow-ups

  1. Compare two investigations: what changed in your method and why?
  2. An AI analyst says the case is resolved. How would you verify that conclusion?
  3. Which links in this attack chain are proven, and which are hypotheses?
  4. What evidence would justify escalation or containment? What would you verify first?
  5. In Operation Loki, what did you personally investigate, and what did another lane establish?
  6. Give a two-minute incident briefing, then explain how your team handled uncertainty.

Rehearse using your own evidence. Bring a question to the booked class; debrief practice uses existing teaching time, with written feedback available through your portfolio.

Try a different question independently

After the included solo labs, request a changed question in AI Investigation Validation or Autonomous APT Investigation. Independently test a specific conclusion, identify an unsupported inference and explain what further evidence would resolve it. The instructor reviews your reasoning separately from platform scoring. During Loki’s existing debrief, explain your individual contribution and handoff.

One instructor-assigned follow-up is included. Use an included lab and your normal monthly launch allowance. Append “Follow-up assessment” to the matching case study, preserving the original. Record the assignment, date and any assistance; mark mixed if guided and independent work coexist.

This is instructor-reviewed practice, not a new automatically scored scenario or a proctored exam. Feedback covers evidence, method, uncertainty and handoff. Certificate criteria are unchanged; no extra live session is included.

Describe the work accurately on your CV

Use “Practical projects” or “SOC lab investigations” and replace these placeholders with your completed work.

Completed simulated SOC investigations using Splunk, including [completed scenarios]. Validated [claim] against [evidence] and documented [finding and limitations]. In a team threat hunt, owned [lane], handed off [finding] and contributed [specific briefing content]. Evidence: [optional portfolio link].

Describe this as practical lab or project experience. Training does not count as employment, replace required years of experience, or guarantee an interview or a job. Employers decide eligibility and selection.

Your nine lessons and team hunt

Loading your next available classes…

Know the terms before you pay

Full refund, no reason needed, any time before your third live session. Sessions count from your first scheduled session after purchase, whether or not you attend. After that, fees are non-refundable. Your checkout shows the exact deadline.

Lifetime access covers the included solo labs, with 12 launches per UTC calendar month. Operation Loki is instructor-led and scheduled; it is not an on-demand solo lab. Live teaching covers nine booked lessons and one team hunt.