ZETLAN TECHNOLOGIES
Course Categories 172+
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
Navigation
Home Business About Us Contact Us All Courses FAQ & Help
Contact Us
+91 8680961847 +91 8680961847 (WhatsApp) info@zetlantechnologies.com
Browse by Domain
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
2000+ Courses · 15+ Technology Domains
Microsoft Cisco AWS EC-Council View All Courses
Home  /  Kali OffSec  /  OSDA
Core · Blue Team

OSDA

OffSec Defense Analyst

Build practical SOC capability by investigating alerts, correlating endpoint and network evidence, detecting attacker behavior and communicating incidents.

Course overview

Skills with real-world context

Designed around the workflows and decisions practitioners use—not a collection of disconnected tool demonstrations.

Build practical SOC capability by investigating alerts, correlating endpoint and network evidence, detecting attacker behavior and communicating incidents. The learning path combines guided concepts, repeatable lab methodology, evidence collection and professional communication.

SOC Analyst Cyber Defense Analyst Threat Monitoring Specialist
2026 market direction

Security operations teams are moving toward behavior-based detection and measurable investigation quality. Analysts who understand attacker techniques and can explain evidence clearly stand out.

Course content

What you will study

A focused six-module roadmap. Exact official syllabus and assessment policies remain subject to OffSec updates.

01

SOC Foundations

SOC roles and workflow
Alert lifecycle and severity
Evidence integrity
Case management and documentation
02

Network Analysis

Traffic and protocol review
DNS and web evidence
Common network attack signals
Packet and flow analysis
03

Windows Detection

Windows event fundamentals
PowerShell and process evidence
Authentication activity
Persistence indicators
04

Linux Detection

Linux logs and processes
SSH and privilege activity
Service and scheduled-task evidence
Common compromise signals
05

Threat Hunting

Hypothesis-led hunting
Indicators versus behaviors
MITRE ATT&CK mapping
Timeline correlation
06

Incident Investigation

Scoping and triage
Root-cause analysis
Containment recommendations
Executive and technical reporting
Plan your preparation

Audience, prerequisites and exam

Who should attend

  • Aspiring SOC analysts
  • IT administrators moving into blue-team work
  • Security professionals building investigation skills

Recommended prerequisites

Networking, Linux and Windows fundamentals. Basic scripting and familiarity with common attack techniques are useful.

Certification assessment

A practical defensive investigation assessment. Review official documentation for the latest platform and report requirements.

Learning outcomes

Capabilities you will build

Triage alerts with consistent methodology
Analyze endpoint, authentication and network logs
Map activity to attacker techniques
Write clear incident findings and recommendations
Primary curriculum reference: Official OSDA course information . Pricing, exam format and availability should always be confirmed with OffSec.