CymBytes Academy · Live with Saahil, from zero

Become a SOC Analyst.

Do the job in a live SOC environment and gain real experience you can show a hiring manager.

Next cycle starts Monday, 14 September 2026

Two ways in. Same live sessions.

The Bootcamp is the first four sessions of the cycle and ends with the SOC L1 Certificate. The Programme is the whole cycle, through to the team threat hunt. Start with the Bootcamp and pay only the difference to continue.

Zero to SOC L1 Bootcamp

Entry

Your first four investigations, live with Saahil

₹1,999

one-time · 4 live sessions · certificate included

Enroll now

Mon, Wed, Fri, Mon · 8:00–9:30 PM IST · join the next cycle · 40 seats

  • Everything in Free
  • 4 live sessions of 90 minutes, live with Saahil on every call
  • Labs 1–4: Splunk First Steps, Windows logs, SPL Detective, Insider Threat
  • Your own scored attempt after every session
  • SOC L1 Certificate with a public verification link
  • Pay only ₹13,000 more to finish the cycle

Zero to SOC L3 Programme

Recommended

Complete beginner to the work an L3 does

₹14,999

one-time · 3 weeks · certificate + readiness report

Enroll now

Mon, Wed, Fri 8:00–9:30 PM IST, live with Saahil · join the next 3-week cycle · 30 seats

  • Everything in the Bootcamp
  • 9 live sessions of 90 minutes, Mon/Wed/Fri at 8 PM IST, live with Saahil on every call
  • All 9 labs: complete beginner to the SOC L3 capstone
  • Operation Loki: a 4-hour live team threat hunt
  • Your own scored attempt after every session, reviewed live
  • SOC L1 Certificate with a public verification link
  • Readiness Report with your score on every lab
  • Recordings, and lab access for 30 days after

See the full programme →

Starts as soon as registration is complete. The email with your lab access is sent immediately after registration. Within 24 hours you also get a Google Calendar invite from Saahil with the Google Meet link for every live session. Live sessions: one lab every Monday, Wednesday and Friday, 8:00–9:30 PM IST, live with Saahil on every call. Operation Loki team hunt: Saturday of week 3, 10:00 AM–2:00 PM IST. Payment by Razorpay, UPI and cards accepted.

Zero to SOC L3 Programme at a glance

3 weeks

Mon, Wed, Fri

8:00–9:30 PM IST

17.5 live hours in total

9 labs

live with Saahil, every one scored

30 seats

per cycle, one teacher

Your first class is free

Sit in on the first session before you pay a rupee.

Every cycle opens with Splunk First Steps on Monday at 8:00 PM IST, live with Saahil. Register free, run lab 1 in your own time, and join the Monday session. No card, no commitment.

Try your first class free

The moment every course skips

Every SOC course page shows you the same things: salary numbers, a wall of tool logos, a certificate to put on LinkedIn.

None of it prepares you for the moment an interviewer says “walk me through an investigation you did” and you have nothing but a course name.

That is what these three weeks are for.

Who this is for

  • Final-year students and recent graduates who want a SOC analyst role and have never touched a SIEM.
  • IT support, NOC, network or sysadmin people moving into security.
  • Anyone with a certificate who freezes when an interviewer says "walk me through an investigation".

The point of all this

What you will be able to say in the interview

Not “I completed a course.” These, in the first person, about work you did with your own hands and can prove.

  • I investigated an insider threat on a live Windows domain and wrote the incident report. It scored 92.
  • I traced a malicious file from the download to the process it spawned, using Sysmon and Splunk.
  • I found a phishing beacon by writing my own SPL, not by clicking an alert.
  • I audited an AI analyst’s investigation and caught the step it missed.
  • I led a lane of a four-hour team threat hunt where no alert had fired, and briefed what we found.
  • Here is my readiness report. Every score on it is verifiable.

Timetable

A lab every Monday, Wednesday and Friday at 8:00 PM IST. Three weeks. Then it repeats.

Register any time. You join the next three-week cycle. Every session is a 90-minute live walkthrough with Saahil, everyone inside their own network; you run a second, solo, scored attempt in your own time. The first four sessions take a complete beginner to the SOC L1 Certificate. The rest is the SOC L1 to L2 path, closed by a four-hour team threat hunt on the Saturday of week 3.

Week 1live with Saahil on every call
  • Monday

    8:00–9:30 PM

    Splunk First StepsFree class

    Search a real Splunk index and answer the first questions a SOC asks of a log.

    Beginner → SOC L1· Zero to SOC L1 Bootcamp

  • Wednesday

    8:00–9:30 PM

    Reading Windows Logs

    Read Windows security and Sysmon events well enough to spot a logon that should not be there.

    Beginner → SOC L1· Zero to SOC L1 Bootcamp

  • Friday

    8:00–9:30 PM

    SPL Detective

    Write your own SPL to hunt across hosts and users instead of clicking through alerts.

    Beginner → SOC L1· Zero to SOC L1 Bootcamp

Week 2live with Saahil on every call
  • Monday

    8:00–9:30 PM

    Insider Threat Investigation

    Run a full investigation on a live domain and write an incident report that scores. Claim the SOC L1 Certificate.

    Beginner → SOC L1· Zero to SOC L1 Bootcamp

  • Wednesday

    8:00–9:30 PM

    Malicious File Execution

    Trace a malicious file from download to execution across endpoint and SIEM telemetry.

    SOC L1 → L2

  • Friday

    8:00–9:30 PM

    Phishing C2 Detection

    Hunt live phishing command-and-control traffic and prove the beacon.

    SOC L1 → L2

Week 3live with Saahil on every call
  • Monday

    8:00–9:30 PM

    AI Investigation Validation

    Audit an AI analyst’s investigation and catch what it missed. The L2 skill of 2026.

    SOC L1 → L2

  • Wednesday

    8:00–9:30 PM

    Autonomous APT Investigation

    Chase an autonomous adversary through a kerberoasting attack chain, end to end.

    SOC L1 → L2

  • Friday

    8:00–9:30 PM

    Review and certificate claims

    Report cards for every lab reviewed live. Certificates claimed on screen. Readiness Reports issued.

    SOC L1 → L2

  • Saturday

    10:00 AM–2:00 PM

    Operation Loki — live team threat hunt

    No alert has fired. For four hours your cycle hunts a live intrusion at a fictional bank across Splunk, endpoints and email, splits the work, and briefs the finding. Saahil runs it; you lead a lane.

    SOC L2 → L3

Next cycle starts Monday, 14 September 2026. Every lab we have is in this programme.

What you leave with

Proof you did the work, not proof you sat through it

SOC L1 Certificate

Issued when you score 70 or more on the four Zero to SOC L1 labs. It carries a public verification link an employer can open.

Readiness Report

Your score on every lab, every checkpoint, every attempt. Evidence of what you can do, not a list of topics you watched.

Recordings + 30 days of lab access

Every live session is recorded and shared with your cycle. Your labs stay open for 30 days after the capstone for re-runs.

What you work with

  • Splunk Enterprise (real, licensed)
  • Windows Server domain controller + workstations
  • Windows Security and Sysmon telemetry
  • SPL search and detection writing
  • Live attacker infrastructure
  • MITRE ATT&CK mapping on every checkpoint

When it starts

Your access starts as soon as registration is complete. The email with your lab access is sent immediately after you register. Within 24 hours you also get a Google Calendar invite from Saahil with the Google Meet link for every live session. Accept it and every session lands in your calendar.

  • Next cycle: Monday, 14 September 2026
  • Live sessions: Mon, Wed and Fri, 8:00–9:30 PM IST, live with Saahil on every call
  • Operation Loki: Saturday of week 3, 10:00 AM–2:00 PM IST

Not sure yet? Start with the Zero to SOC L1 Bootcamp.

₹1,999 for the first four sessions: labs 1–4 taught live by Saahil, plus the SOC L1 Certificate. If you continue into the full programme, you pay only the ₹13,000 difference. Compare the options →

Already finished the Bootcamp? Pay the ₹13,000 balance and finish the cycle →

Questions

Straight answers

Is the first class really free?
Yes. Monday of week 1, Splunk First Steps, is open to anyone with a free account. Register, run lab 1 in your own time, and the Meet link for the Monday session arrives with your lab 1 report card. If you like it, enroll and the rest of the cycle is yours.
Do I need any background?
No. Monday of week 1 starts from your first Splunk search. If you can use a browser and follow instructions, you can start. Basic Windows familiarity helps.
When does it start?
Your labs open the moment you register. The live sessions run on a rolling three-week cycle, Mon, Wed and Fri, 8:00–9:30 PM IST, and a new cycle starts every third Monday. You join the next one; the exact date is on this page and in your welcome email. Within 24 hours you also get a Google Calendar invite from Saahil with the Google Meet link for every live session.
I already work in a SOC. Is this too basic?
The first four sessions assume nothing and get you the L1 certificate. The rest is the work L2 analysts do: malware execution chains, C2 hunting, auditing an AI investigation, an autonomous adversary. The capstone is a four-hour proactive hunt with no alert, run as a team. That is where working analysts sweat.
What does a session look like?
Ninety minutes, live with Saahil on every call. He walks the whole cycle through that day’s lab, everyone inside their own copy of the network. You then run a second, solo, scored attempt in your own time. Friday of week 3 is the live review of everyone’s report cards.
Is this a recording of someone else’s lab?
No. Each student gets their own live Windows domain and Splunk server on cloud infrastructure. The attacks run inside your network during your session, and the logs you investigate are yours.
Do I need to install anything?
No. Everything opens in the browser. A laptop with a stable connection is enough.
What if I miss a session?
Watch the recording and do the lab attempt before the week 3 review. Or attend that lab in the next cycle; your access covers it.
What is the refund policy?
Full refund at any point during your access period, no reason needed. Details are on the refund policy page.
Do you help with jobs?
We give you a verifiable certificate and a scored readiness report you can put in front of a hiring manager, and we will tell you honestly where you stand. We do not run placements.

Three weeks from now, you will have done the job. All of it.

Next cycle starts Monday, 14 September 2026. Your labs open the day you register.

Mon, Wed and Fri, 8:00–9:30 PM IST · 30 seats per cycle · ₹14,999 one-time · full refund at any point during your access.

Questions? Email sales@cymbytes.com. Refund terms: refund policy.