Entry-Level SOC Analyst Certification

SOC Analyst Training & Certification - CCDL1

The industry's most practical blue team certification for aspiring SOC Analysts. Learn to detect, investigate, and respond to cyber attacks through real-world investigations.

Real-World Readiness

Train SOC analysts with real cyber incident simulations.

Job-Ready Skills

Developed with Mandiant & PwC SOC Managers to build the skills they hire for.

Industry Aligned

90% aligned with NIST Cyber Defense Analyst role.

Modern & Evolving Content

Up-to-date SOC training with AI, AWS, and Azure Sentinel labs

Certify Your Team

Who It's For

Aspiring SOC/Security Analysts

Individuals looking to start a cybersecurity career and gain the core skills required for Security Operations Center roles.

Students

Learners who want a clear, guided path to their first SOC role with practical experience instead of theory.

Career Switchers

Those looking to transition into the defensive side of cybersecurity through structured, hands-on blue team training and certification.

Team Managers & SOC Leads

Organizations seeking a standardized, real-world training and certification program to onboard and validate entry-level analysts quickly.

What You'll Learn

Through the CCDL1 program, you'll gain the essential technical and analytical skills every SOC analyst needs, built entirely around real-world investigations

1

Operate in a SOC

Perform end-to-end SOC workflows including detection, triage, escalation, and reporting

2

Master SIEM Operations

Use SIEM tools like Microsoft Sentinel to detect, investigate, and visualize threats.

3

Investigate Security Alerts

Correlate multi-source logs to detect, validate, and prioritize real cyber incidents.

4

Conduct Digital Forensics

Acquire, preserve, and analyze digital evidence to trace attacker activities.

5

Respond to Incidents

Contain, eradicate, and recover from security breaches through structured IR processes.

6

Build Confidence

Apply your SOC skills to investigate and respond to real cyber incidents.

Curriculum

Essential skills every SOC analyst needs

1. SOC Operations & Threat Intelligence

Start your blue-team journey by understanding how Security Centers (SOCs) function, triage alerts, and leverage threat intelligence to detect and prioritize real-world cyberattacks.

2. Network & Endpoint Security

Learn how to protect enterprise infrastructure by monitoring network traffic, detecting intrusions, and securing endpoints against malware, exploits, and lateral movement.

3. SIEM Operations & Log Analysis

Gain hands-on experience in using SIEM platforms to collect, correlate, and analyze log data sharpening the detection and investigation skills every SOC analyst needs.

4. Email Security & Phishing Defense

Identify and analyze phishing attempts, spoofing, and business email compromise (BEC) attacks — using hands-on labs to build strong detection and response capabilities.

5. Digital Forensics & Incident Response (DFIR)

Master evidence acquisition, log and disk forensics, and coordinated response workflows to investigate and contain real incidents through practical, investigation-driven labs.

6. Cloud Forensics & AI-Driven Security

Explore modern cloud environments, apply forensic techniques to cloud incidents, and use AI-based detection tools to enhance threat visibility and automated response.

Real Feedback from SOC Analysts

Hear It Straight from the Defenders

@SANSInstitute

"The Team or Practitioner of the Year Award 🏆 goes to the individual or team who has done extraordinary work in #CyberSecurity. The Community Winner for 2023 goes to @CyberDefenders. Congratulations! #SANSDMA"

Paweł Mazur

Security Engineer @IBM

"Cool SWAG from CyberDefenders ;) #ccd #blueteam #soc"

Black Hat MEA

"Join industry leaders like Offensive Security, NotSoSecure Training part of Claranet Cyber Security, Mandiant (now part of Google Cloud), CyberDefenders, CQURE Inc., and many more for cutting-edge courses both pre and post-event. Whether you're a beginner or an experienced professional, our diverse training offerings will elevate your expertise to new heights. 🌟 Don't miss this opportunity to learn from the best and stay ahead in the rapidly evolving world of cybersecurity. Secure your spot now: bit.ly/451j5Hy #BlackHatMEA #CybersecurityTraining #ExpertCourses #StayAhead #TechEducation #LevelUpSkills"

Sai Dinesh Kondeti

Security Engineer @Microsoft

"I feel extremely happy and proud to share that I have successfully completed #CertifiedCyberDefender certification. This is an intermediate-to-advanced level course/cert from CyberDefenders, I can say that this is some high quality content that I have seen/studied in recent times. Labs are the meat of this course, sometimes, I had to spend several hours just to answer a single question in these labs. Speaking about the brutal 48 hours exam, it covers almost all major domains in CyberDefense. Exam grading process was unique wherein the students should not only provide the answer but also the approach that they have taken to reach that answer. Overall, I am happy that I have taken this course and proud that I have completed this certification exam, cannot wait to touch the shiny physical gold coin which I would be receiving as a token of achievement. #ccd #DefendSmarterNotHarder #cyberdefense #goldcoin #achievement #learningandgrowing"

Paweł M.

GIAC Advisory Board | SIEM Correlation Engineer @IBM

"That was a tough one. Managed to score more than 90% to receive that gold coin. Overall, I consider this to be one of the best Blue Team cert you can get"

Vee Widmann

SOC Analyst @F5

"Stoked to start the CyberDefenders CCD program next week! Cheers to always learning! #blueteam #socanalyst #cyberdefenders"

Lucas Matias

SOC Analyst @Kaspersky

"Few months of study, practice here, practice there, and then the reward came! Thanks CyberDefenders for the solid learning content, and even more for the knowledge and endurance test that was the exam. I`ll surely recommend #CCD to everyone."

Arion Martin

SOC Analyst @ WhiteDog

"Overall, I’m extremely pleased with the course content delivery, exam experience, and how the CyberDefenders team coaches their students through the “smarter, not harder” mentality. I think this is incredibly beneficial in real-world applications. Finally finished the review of my experience with the course and the exam after passing it a few months ago, so give it a read if you're interested."

Thomas Schuddinck

Senior CyberSecurity Consultant @PwC

"Yesterday, we launched the epic first edition of DefendNight at PwC Belgium! 🚀 Our blue team, along with our amazing IAM, AppSec, OffSec, OT operatives—and many more—banded together to fortify our defenses against cyber threats. Utilizing the CyberRange platform from CyberDefenders, we embarked on an fun and insightful mission to hunt down cyber threats across endpoints, networks, and the cloud. 🌐💻 And of course, our operations were fueled by some tactical pizza! 🍕 It was an unforgettable night of cyber co-op and defense excellence. We're already gearing up for the next DefendNight! 🔥🔒 #CyberSecurity #TeamPwC #DefendNight #ThreatHunting #EndpointForensics #NetworkForensics #CloudForensics #BlueTeam #CyberDefenders #SecOps #Pizza Jeroen Hoof Cedric Lambrecht Mike Van Camp Wout De Ceuninck Tûba Kilinç Laurent Lombaerts Andreas M. Liam Deferm"

Manos Vordakis

Senior Security Analyst @ Accenture

"Definitely the most challenging exam I've taken to this day. In 48 hours, my skills were tested in Threat Hunting, Disk, Memory, and Network Forensics and also in Perimeter Defense. The labs were challenging and the exam experience was flawless. The best part of the course is that the CyberDefenders team is really trying to teach you how to think and research, so be prepared to take the extra step. Thank you CyberDefenders for this amazing course!"

Medet Merkebaiuly

Senior Cybersecurity Engineer @Kcell JSC

"I chose this course for a reason. In mid-July, I wanted to dive into this course and take the exam because I was deeply impressed by the complexity and thoughtfulness of the challenges on the CyberDefenders platform. Pursuing this goal, I enrolled in this course, and I have no regrets at all. The course itself is well-designed and offers a range of modules covering various aspects of cybersecurity. The lab tasks are exceptional. Despite my experience as a SOC L1 and L2 analyst, I often found myself spending 8-9 hours on a single lab assignment. There was even one time when it took me a week to find the right answer to a single question!"

Mohammad Askar

Offensive Security Engineer at Amazon

"I'm really glad to witness the extraordinary growth of CyberDefenders, the team was putting great efforts into creating high-quality content and labs for our blue teams across the globe and they definitely deserve your support."

Luis Ricardo Lüscher

Cyber Security Analyst @Swisscom

"One of the highlights of my preparation was engaging with the fantastic labs in the CCD preparation course offered by CyberDefenders. These hands-on labs were instrumental in sharpening my skills and boosting my confidence. Grateful for this learning opportunity and excited to share my insights and experiences in an upcoming review. Stay tuned! Now, looking forward to the next milestones and certifications in my cyber security journey! 🚀 #CertifiedCyberDefender #CCD #CyberSecurity"

Alwin Lau

Penetration Tester at EY

"I am thrilled to announce that I have successfully completed and passed the Certified CyberDefender (CCD) training and certification. This vendor-neutral, hands-on cyber defense training has been an incredible journey, equipping me with the skills and knowledge to become a part of the next generation of SOC analysts, blue teams, and security engineers. I would also like to extend my thanks to my peers, mentors, and everyone who has supported me throughout this journey. Your encouragement and guidance have been invaluable. For anyone interested in pursuing a career in cybersecurity, I highly recommend the Certified CyberDefender course. You can find more information about the course here: lnkd.in/g3enkaTW CyberDefenders Mohammed Hasan Muhammad Alharmeel Here's to a safer and more secure digital world! #CertifiedCyberDefender #CyberSecurity #BlueTeam"

Alejandro Zaratiegui Bautista

System admin @Tigloo

"🔥 Thrilled and honored to now be a #CertifiedCyberDefender! 🛡️ Passed the 48 hours hands-on and feeling privileged to join the ranks 🚀 CyberDefenders #CCD #CyberDefenders #DFIR #BlueTeam #InfoSec #SOC No os voy a mentir, ha sido un examen de gran nivel. Durante los últimos 5 meses he estado preparándome para el CCD a al vez que trabajaba. Han sido unos meses de mucho esfuerzo, pero como siempre digo, el esfuerzo gana al talento y con constancia y disciplina todo el posible. En cuanto al examen, han sido 48 horas con 5 secciones divididas en Network Forensics, Disk Forensics, Perimeter Defense, Memory Forensics y Threat Hunting. ¡Siento que he adquirido muchísimos conocimientos y no me esperaba menos, ya que es una de las certifiaciones Blue Team más reconocidas! Ahora, con la certificación en mano, me siento más fuerte y preparado para los desafíos del mundo de la ciberseguridad. Este logro es un testimonio de que el esfuerzo sostenido puede superar cualquier obstáculo. #CyberDefenders #CCD #DefendSmarterNotHarder #blueteam #cybersecurity #cybersec See translation"

Rodrigo Wanderson

Threat Response Analyst @Kaspersky

"🚀 Transform into a Cyber Defender in 48 Hours: My Certification Journey on 1st attempt 🚀 🌟 Achieving the #CertifiedCyberDefender credential marks a key milestone in my cybersecurity career! The intensive 48-hour experience was both challenging and enriching, allowing me to join the elite ranks of cybersecurity professionals. CyberDefenders #CCD #CyberDefenders #DFIR #BlueTeam #InfoSec #SOC The CCD exam tested my abilities with real-world scenarios and complex problem-solving, and the recent addition of educational videos further enhances the course for new participants. Broadened Skills: 🛡️ SecOps Fundamentals 🚧 Perimeter Defense 🔍 Threat Hunting 🚨 Incident Response 🔍 Digital Forensics 🕵️‍♂️ Evidence Collection 💾 Disk Forensics 🧠 Memory Forensics 🌐 Network Forensics 🔗 Embark on your journey to becoming a Cyber Defender: Link: lnkd.in/dqDZMyHU Discover the course details and unlock potential discounts. A Nod to My Fellow Cyber Defenders To all current and aspiring Cyber Defenders: Your dedication is inspiring. Together, we are fortifying the digital world. 🛡️ #DefendSmarterNotHarder And of course, a special and heartfelt thanks to Kaspersky ❤️ for their crucial support and guidance in this journey – it was instrumental in my achievement. #CyberThreatHunting #IncidentResponse #BlueTeam #DigitalForensics #DFIR #CyberDefense #ThreatHunting #SecurityOperations #SOC #DiskForensics #MemoryForensics #NetworkForensics #NewYearNewChallenges"

Guillaume Benats

Senior Security Analyst @Microsoft

"Certified CyberDefenders - One of the best exam I have taken so far in the blue team realm for the price/quality ratio! Recommended to bring a team of analysts up-to-speed. Course brings all fundamentals DFIR aspects, with something to learn for everyone. The added-value resides in the challenging but realistic labs and exam, practical only, manually evaluated to assess how you think a problem, validating your skills in threat hunting and forensics. #ccd #certifiedcyberdefender"

Mateus Salgado

SOC Analyst @Kaspersky

"I decided to embark in the CCD (Certified CyberDefender) certification journey. Here we have 4 months to learn a solid content about the main topics that a defender guy 🛡️need to master : ✔️SecOps Fundamentals ✔️Perimeter Defense ✔️Threat Hunting ✔️Evidence Collection ✔️Disk Forensics ✔️Memory Forensics ✔️Network Forensics ✔️Incident Response ❌Malware Analysis (recently introduced, so it wasn't part of my exam) Afterwards this learning phase, it's time to get our hands dirty and jump into a 48h exam where we are going to validate whether we really LEARNED 📝everything that was proposed with extremely realistic scenarios that will make you melt your brain to find the right answer/evidence.🤯 Sooo, after a weekend (starting on Friday 09am and ending on Sunday 09am - and yes, I spent even my last minute⌛to tweak a bit one of the questions) in this insane vibe + 10 business day waiting for the grading phase (anxiety? It's over 9000!), I can finally celebrate🕺🎉🍾! Now I am a guy who defend smarter, not harder! I am a CyberDefenders Certified 🕵️‍♂️🧠!"

Abdiel N.

Cybersecurity Forensics Analyst @Microsoft

"CyberDefenders keeps coming out with some #quality #labs. This most recent one covers #cloudforensics #hunting in #Azure with Elastic. Really great for anyone wanting to gain some #exposure to Azure #logdata. I hope everyone has a great Monday! :D lnkd.in/enYiPhSs"

Day Johnson

Detection Engineering & Research @ Datadog Detection Engineering & Research @ Datadog

"Phew! This was a challenging one but I made it through. Major props to the CyberDefenders team for their work on this. Achieving this credential is no easy feat. Review and exam experience videos are underway, per usual. Keep an eye out! #cybersecurity #CyberDefenders #CCD #CertifiedCyberDefenders"

Bret W.

Senior Incident Response Engineer

"While out of town on the other side of the US for work, my coin arrived for becoming a Certified Cyber Defender (#CCD) from CyberDefenders!"

Lukasz Jalowiecki

Senior SIEM/SOC Analyst at ET&S

"So proud of this one 😎 . Big thanks to the CyberDefenders team for creating and maintaining this cert (+ for the coin)! #CCD"

ANY.RUN

Interactive Malware Analysis Service

"#ANYRUN 🤝 CyberDefenders Great news! Now our service is integrated into CyberDefenders' security training courses. Find out how to improve your skills and get 10% off for all trainings 😎👇 lnkd.in/gchYf7D6 #training #security #courses #cyberdefenders #soc #cybersecurity"

Day Johnson

Detection Engineering @Datadog

"🔒My first impressions on the Certified CyberDefender - a new practical Blue Team Certification from CyberDefenders aimed towards SOC Analysts. Everything from the syllabus, labs and even potential competition. All in todays video. #cybersecurity #socanalyst #incidentresponse #digitalforensics #detectionandresponse"

Jason Taylor

GCIH | OSCP | CySA+ GCIH | OSCP | CySA+

"Got my CyberDefenders coin for passing the #CCD!"

Varakorn Chanthasri

Senior Cybersecurity Consultant @Bluebik Group PLC.

"🎉 Achievement Unlocked: Certified CyberDefender (CCD) 🚀 I am thrilled to announce that I have successfully passed the Certified CyberDefender (CCD) exam! 🏆 This practical exam was no small feat, requiring me to demonstrate my skills within a 48-hour timeframe. Despite the limited practice time, I proudly nailed it on my very first attempt! I owe a huge debt of gratitude to the incredible CyberDefenders team. Their course content is nothing short of excellent, aligning seamlessly with real-world applications. The exams were not just educational but enjoyable and challenging. What truly sets them apart is their ability to craft practical exams that comprehensively cover all essential topics. It's nothing short of outstanding! I can't wait to put my CCD certification to good use and continue my journey in the world of cybersecurity. 🛡️💼 #CCDCertified #CyberDefender #CybersecurityJourney #AchievementUnlocked #DFIR #SOCAnalyst #ThreatHunting #DiskForensics #NetworkForensisc #MemoryForensics Thank you all for your support and encouragement on this remarkable journey!"

Krzysztof Kuzin

SOC L2 Analyst

"A really great addition (SWAG) to 𝑪𝑪𝑫 𝑪𝒆𝒓𝒕𝒊𝒇𝒊𝒄𝒂𝒕𝒊𝒐𝒏 from CyberDefenders. I was waiting to publish this one - the whole set should include bag, cup and stickers - but the (German) DHL failed to deliver the stickers (sent back without notification). Now I'm waiting for the CCD challenge 𝐂𝐎𝐈𝐍 and more labs/challenges on the platform... and maybe next level certifications! 😎"

Akshat Gupta

Threat Hunting and Intelligence Analyst

"{sigh} So I passed my 48-hour Certified CyberDefender Certification. Been going rough these past 6 months, and I'm super happy to achieve it. This cert is difficult on another level. Nevertheless, I enjoyed it. Thanks, CyberDefenders team. Your content is top notch!! ❤️"

Matt Daugherty

Security Analyst @UFP Industries

"Woohoo! 8 hours and 35 minutes; I have finally completed the Disk Forensics Lab. I am extremely impressed with CyberDefenders' Certified CyberDefender Blue Team Training. The training content is extensive, and the labs are no joke. I highly recommend for anyone looking to get into Cybersecurity. CyberDefenders"

Jason Taylor

Senior Security Analyst @Oklahoma Fidelity Bank

"Check out my review of the Certified CyberDefender (CCD) course and exam by CyberDefenders. Overall, it was a genuinely fun experience, and I learned a lot about digital forensics, incident response, and threat hunting. After the course I was able to apply a lot of what I had learned on the forensics topics directly to my job. Thanks to Muhammad Alharmeel and Ahmed Shawky for creating this awesome course and exam experience! Looking forward to seeing the CCD start gaining some traction in the job market! As a practical, hands-on exam, passing the CCD means you actually have used tools like Nessus, Sentinel, Elastic, Volatility, and actively performed Incident Response and investigations on forensic artifacts. #cyberdefenders #blueteam #certified"

Lukasz Jalowiecki

Senior SIEM/SOC Analyst at ET&S

"Happy to share that I'm now #ccd certified:) For anyone looking for a well-structured, intermediate level blue team course with practical exam, it's one of the best out there. #DefendSmarterNotHarder #cyberdefenders"

@ArsenalRecon

"Did you know that Arsenal Image Mounter is showcased in @CyberDefenders blue team training? If you aren't familiar with what they do, check out cyberdefenders.org. They also have a Discord server that is much, much more active than our own! 😂 #DFIR"

@GuidedHacking

"🚀Join us as we complete @cyberdefenders RE101 📚6 Challenges for Beginner Malware Analysts 🔍Extracting Encrypted Flags 🔓Decoding in CyberChef 🔧Fixing file headers 🔎Used a debugger to find a flag 🔐Xor Encrypted Strings 🔗youtu.be/_lzPubejr4U"

@Myrtus0x0

"@cyb3rops 100% agreed. Personally a big fanof cyberdefenders.org. Done of a couple of those and they also have a bunch of the FLAREOn problem sets which is always great for practice"

@B1N2H3X

"Another one of the @MagnetForensics 2022 #CTF devices is live for play on @CyberDefenders! Give the Mr. Gamer questions a go and test your Linux #DFIR skills cyberdefenders.org/blueteam-ctf-challenges/97"

@malmoeb

"Solving BSidesJeddah-Part1 from @CyberDefenders (partially) with NetworkMiner from @netresec. I think NetworkMiner is awesome - extracting files, analyzing sessions, and parsing mail 🤩 Then, use Wireshark for the more detailed questions. #CyberSecurity"

@netresec

"Nice writeup on how you can solve @malware_traffic's "Malware Traffic Analysis 1" challenge on @CyberDefenders using NetworkMiner, Wireshark and VirusTotal. systemweakness.com/rig-exploitation-kit-infection-malware-traffic-analysis-70fd1b430fdc"

@jstrosch

"A great way to learn and practice new skills is through a #ctf. @CyberDefenders provides an excellent (and free!) platform to do just that. I've got a few challenges added there as well, check it out :) 🧩 cyberdefenders.org/search/labs/?q=oledump"

@jbeley

"@Golgothus @CG_iSecurity I love @CyberDefenders challenges. Not only is it great way to keep my own skills up...but wait there's more...it's great for testing your tools....DFIR LPT: always validate your tools..."

@BlackMatter23

"Our annual global technical training #CyberPolygon is starting tomorrow. The main theme is Supply Chain attacks. Don't worry if you haven't registered, we'll post all 4 DFIR+TH challenges on @CyberDefenders site. Good luck to all teams, have a fun👍 cyberpolygon.com/scenarios"

@antoniosanzalc

"The fine people of @CyberDefenders have put an amazing load of #DFIR CTF here: cyberdefenders.org/labs Learn & have fun !"

@4n6lady

"Check out some great #BlueTeam challenges from @CyberDefenders. Am currently getting setup with Splunk for their first Boss of the SOC challenges 🤩 Cyberdefenders.org"

View all testimonials

FAQ
Common questions about CCDL1.

Need More Information? Visit our Help Center for detailed articles about the CCDL1 certification, exam preparation, and more.

Learn the SOC skills that get you hired

Join thousands who've launched their careers and built real SOC muscle

Blue Team Training for SOC analysts and DFIR - CyberDefenders