Skip to content

SOC Investigation Course · SOC L1 preparation

Practise the investigation. Explain your decisions in the interview.

Applying for junior SOC roles? Build practical lab experience in Splunk, Windows logs, malicious execution and phishing-related C2 activity, with evidence of your own work.

₹5,999 one-time · six live classes · six labs

New to Splunk? Start with the ₹1,999 Foundations Bootcamp and upgrade for ₹4,000. Compare all offers.

Build on the foundations with malware and phishing-related C2 investigations, scored practice and evidence of the decisions you make.

Live teaching
4 evenings + 2 Saturdays · 6 × 60 min
Included labs
6 labs · lifetime access
Practice allowance
10 launches per calendar month
What you build
Scored lab records + an investigation portfolio
  1. 1. Search Splunk

    Find the right index, inspect events and answer questions with evidence.

  2. 2. Read Windows logs

    Interpret logons, process activity and Sysmon events.

  3. 3. Write SPL investigations

    Compare hosts and users, build timelines and test a hypothesis.

  4. 4. Explain an incident

    Investigate an insider threat and write findings with a containment recommendation.

  5. 5. Trace malicious execution

    Connect download, process and network evidence; distinguish an attempted action from a confirmed outcome.

  6. 6. Investigate phishing-related C2

    Test a beaconing hypothesis and document supporting indicators and limitations.

Submit an incident report and earn a final score of 70 or more in each of the four required foundation labs, with a plan that includes the certificate.

Paid-program commitment: we help you build hiring evidence from your scored investigations and written case studies. When it is ready, and only with your permission, CymBytes will share it with relevant recruiters. This is included only in paid programs.

Build a portfolio of scored labs and your written investigation. Download your evidence pack or choose to publish a link. Instructor feedback is available through your portfolio. Recruiter sharing is consent-based and does not guarantee an interview or placement.

Bring a laptop and a stable internet connection. Ask questions during live class and use your portfolio to request feedback on a complete scored investigation. If you miss a class, contact the instructor to arrange a repeat or ask about recording availability.

Job-to-lab checklist, investigation worksheet, interview debrief prompts and one instructor-assigned follow-up exercise with portfolio feedback. Practice uses your included labs and monthly launch allowance. See the preparation guide.

Lifetime access covers the included solo practice labs; Operation Loki, where included, is instructor-led and scheduled. Live teaching covers the booked sessions; it is not an unlimited live-class subscription. Monthly launches reset on the first day of each UTC calendar month.

Connect the job description to your practice

Bring a posting you want to apply for. Match each responsibility to the exercises below, then record what you have demonstrated and what you still need to learn. These are curriculum matches, not employer endorsements.

Search and investigate SIEM events

Splunk First Steps · SPL Detective

All paid options

Evidence to build: Your searches, why you chose them, and the events supporting your conclusion.

Investigate suspicious Windows activity

Reading Windows Logs · Insider Threat Investigation

All paid options

Evidence to build: A timestamped account of affected users and hosts, alternative explanations and a written handoff.

Trace malicious execution

Malicious File Execution

Investigation Course + Complete

Evidence to build: A download-to-execution timeline, relevant process evidence and a justified escalation.

Investigate phishing-related C2 activity

Phishing C2 Detection

Investigation Course + Complete

Evidence to build: Indicators, connections and evidence for or against a beaconing hypothesis. This is not a complete email-security product course.

Collaborate and brief an investigation

Operation Loki

Complete only

Evidence to build: Your assigned lane, individual findings, team handoff and briefing contribution.

Check gaps separately: networking and Linux fundamentals, Sentinel/QRadar or EDR product experience, ServiceNow workflows, shift procedures, certifications, location and required employment experience. The six-lab course does not demonstrate all of these. Operation Loki belongs to the Complete programme.

Turn each lab into evidence you can explain

Job-to-lab checklist, investigation worksheet, interview debrief prompts and one instructor-assigned follow-up exercise with portfolio feedback. Practice uses your included labs and monthly launch allowance.

  1. Complete the included lab and save your selected queries, results, timeline, conclusion and escalation recommendation.
  2. Write the case study in My portfolio. Declare whether the work was guided, independent or mixed.
  3. Use the prompts below to rehearse a two-minute walkthrough. Bring one question to your booked class; the debrief uses existing class time.
  4. After completing the labs in your offer, ask the instructor during class or through your portfolio for a different investigation question in one of those labs. Attempt it without a walkthrough and disclose any help used.
  5. Label the follow-up separately in the same case study, save and submit for instructor feedback. Feedback covers evidence, reasoning, limitations and handoff. Revise before publishing.

The follow-up is an instructor-reviewed practice assessment using a changed question in an existing lab. It is not a new automatically scored scenario or a proctored certification exam. Your platform lab score and certificate criteria stay separate. No extra live session is included.

Practise these interview follow-ups

  1. What question were you trying to answer, and what did you check first?
  2. Which query or event supports your conclusion? Explain its fields and time range.
  3. What benign explanation did you test? What would change your conclusion?
  4. Which users and hosts are affected, and what remains unknown?
  5. Would you escalate? Explain priority, evidence and the next action you recommend.
  6. Explain the investigation in two minutes, then answer a follow-up without reading your report.

Use your own evidence. A memorised answer is not a demonstration that you can investigate.

Describe the work accurately on your CV

Use a “Practical projects” or “SOC lab investigations” section. Only include work you completed and can explain.

Investigated [scenario] in a simulated enterprise lab using Splunk. Used [queries and events] to establish [finding], documented the timeline and recommended [next action]. Evidence: [your report link].

Describe this as practical lab or project experience. Training does not count as employment, replace required years of experience, or guarantee an interview or a job. Employers decide eligibility and selection.

Your next six classes

Loading your next available classes…

Full refund, no reason needed, any time before your third live session. Sessions count from your first scheduled session after purchase, whether or not you attend. After that, fees are non-refundable. Refund policy.