What you will study
A focused six-module roadmap. Exact official syllabus and assessment policies remain subject to OffSec updates.
Build practical SOC capability by investigating alerts, correlating endpoint and network evidence, detecting attacker behavior and communicating incidents.
Designed around the workflows and decisions practitioners use—not a collection of disconnected tool demonstrations.
Build practical SOC capability by investigating alerts, correlating endpoint and network evidence, detecting attacker behavior and communicating incidents. The learning path combines guided concepts, repeatable lab methodology, evidence collection and professional communication.
Security operations teams are moving toward behavior-based detection and measurable investigation quality. Analysts who understand attacker techniques and can explain evidence clearly stand out.
A focused six-module roadmap. Exact official syllabus and assessment policies remain subject to OffSec updates.
Networking, Linux and Windows fundamentals. Basic scripting and familiarity with common attack techniques are useful.
A practical defensive investigation assessment. Review official documentation for the latest platform and report requirements.