Search and investigate SIEM events
Splunk First Steps · SPL Detective
All paid options
Evidence to build: Your searches, why you chose them, and the events supporting your conclusion.
SOC Investigation Course · SOC L1 preparation
Applying for junior SOC roles? Build practical lab experience in Splunk, Windows logs, malicious execution and phishing-related C2 activity, with evidence of your own work.
₹5,999 one-time · six live classes · six labs
New to Splunk? Start with the ₹1,999 Foundations Bootcamp and upgrade for ₹4,000. Compare all offers.
Build on the foundations with malware and phishing-related C2 investigations, scored practice and evidence of the decisions you make.
1. Search Splunk
Find the right index, inspect events and answer questions with evidence.
2. Read Windows logs
Interpret logons, process activity and Sysmon events.
3. Write SPL investigations
Compare hosts and users, build timelines and test a hypothesis.
4. Explain an incident
Investigate an insider threat and write findings with a containment recommendation.
5. Trace malicious execution
Connect download, process and network evidence; distinguish an attempted action from a confirmed outcome.
6. Investigate phishing-related C2
Test a beaconing hypothesis and document supporting indicators and limitations.
Submit an incident report and earn a final score of 70 or more in each of the four required foundation labs, with a plan that includes the certificate.
Paid-program commitment: we help you build hiring evidence from your scored investigations and written case studies. When it is ready, and only with your permission, CymBytes will share it with relevant recruiters. This is included only in paid programs.
Build a portfolio of scored labs and your written investigation. Download your evidence pack or choose to publish a link. Instructor feedback is available through your portfolio. Recruiter sharing is consent-based and does not guarantee an interview or placement.
Bring a laptop and a stable internet connection. Ask questions during live class and use your portfolio to request feedback on a complete scored investigation. If you miss a class, contact the instructor to arrange a repeat or ask about recording availability.
Job-to-lab checklist, investigation worksheet, interview debrief prompts and one instructor-assigned follow-up exercise with portfolio feedback. Practice uses your included labs and monthly launch allowance. See the preparation guide.
Lifetime access covers the included solo practice labs; Operation Loki, where included, is instructor-led and scheduled. Live teaching covers the booked sessions; it is not an unlimited live-class subscription. Monthly launches reset on the first day of each UTC calendar month.
Bring a posting you want to apply for. Match each responsibility to the exercises below, then record what you have demonstrated and what you still need to learn. These are curriculum matches, not employer endorsements.
Splunk First Steps · SPL Detective
All paid options
Evidence to build: Your searches, why you chose them, and the events supporting your conclusion.
Reading Windows Logs · Insider Threat Investigation
All paid options
Evidence to build: A timestamped account of affected users and hosts, alternative explanations and a written handoff.
Malicious File Execution
Investigation Course + Complete
Evidence to build: A download-to-execution timeline, relevant process evidence and a justified escalation.
Phishing C2 Detection
Investigation Course + Complete
Evidence to build: Indicators, connections and evidence for or against a beaconing hypothesis. This is not a complete email-security product course.
Operation Loki
Complete only
Evidence to build: Your assigned lane, individual findings, team handoff and briefing contribution.
Check gaps separately: networking and Linux fundamentals, Sentinel/QRadar or EDR product experience, ServiceNow workflows, shift procedures, certifications, location and required employment experience. The six-lab course does not demonstrate all of these. Operation Loki belongs to the Complete programme.
Job-to-lab checklist, investigation worksheet, interview debrief prompts and one instructor-assigned follow-up exercise with portfolio feedback. Practice uses your included labs and monthly launch allowance.
The follow-up is an instructor-reviewed practice assessment using a changed question in an existing lab. It is not a new automatically scored scenario or a proctored certification exam. Your platform lab score and certificate criteria stay separate. No extra live session is included.
Use your own evidence. A memorised answer is not a demonstration that you can investigate.
Use a “Practical projects” or “SOC lab investigations” section. Only include work you completed and can explain.
Investigated [scenario] in a simulated enterprise lab using Splunk. Used [queries and events] to establish [finding], documented the timeline and recommended [next action]. Evidence: [your report link].
Describe this as practical lab or project experience. Training does not count as employment, replace required years of experience, or guarantee an interview or a job. Employers decide eligibility and selection.
Loading your next available classes…
Full refund, no reason needed, any time before your third live session. Sessions count from your first scheduled session after purchase, whether or not you attend. After that, fees are non-refundable. Refund policy.