SOC Analyst Training & Certification - CCDL1
The industry's most practical blue team certification for aspiring SOC Analysts. Learn to detect, investigate, and respond to cyber attacks through real-world investigations.
Real-World Readiness
Train SOC analysts with real cyber incident simulations.
Job-Ready Skills
Developed with Mandiant & PwC SOC Managers to build the skills they hire for.
Industry Aligned
90% aligned with NIST Cyber Defense Analyst role.
Modern & Evolving Content
Up-to-date SOC training with AI, AWS, and Azure Sentinel labs
Who It's For
Aspiring SOC/Security Analysts
Individuals looking to start a cybersecurity career and gain the core skills required for Security Operations Center roles.
Students
Learners who want a clear, guided path to their first SOC role with practical experience instead of theory.
Career Switchers
Those looking to transition into the defensive side of cybersecurity through structured, hands-on blue team training and certification.
Team Managers & SOC Leads
Organizations seeking a standardized, real-world training and certification program to onboard and validate entry-level analysts quickly.
What You'll Learn
Through the CCDL1 program, you'll gain the essential technical and analytical skills every SOC analyst needs, built entirely around real-world investigations
Operate in a SOC
Perform end-to-end SOC workflows including detection, triage, escalation, and reporting
Master SIEM Operations
Use SIEM tools like Microsoft Sentinel to detect, investigate, and visualize threats.
Investigate Security Alerts
Correlate multi-source logs to detect, validate, and prioritize real cyber incidents.
Conduct Digital Forensics
Acquire, preserve, and analyze digital evidence to trace attacker activities.
Respond to Incidents
Contain, eradicate, and recover from security breaches through structured IR processes.
Build Confidence
Apply your SOC skills to investigate and respond to real cyber incidents.
Curriculum
Essential skills every SOC analyst needs
1. SOC Operations & Threat Intelligence
Start your blue-team journey by understanding how Security Centers (SOCs) function, triage alerts, and leverage threat intelligence to detect and prioritize real-world cyberattacks.
2. Network & Endpoint Security
Learn how to protect enterprise infrastructure by monitoring network traffic, detecting intrusions, and securing endpoints against malware, exploits, and lateral movement.
3. SIEM Operations & Log Analysis
Gain hands-on experience in using SIEM platforms to collect, correlate, and analyze log data sharpening the detection and investigation skills every SOC analyst needs.
4. Email Security & Phishing Defense
Identify and analyze phishing attempts, spoofing, and business email compromise (BEC) attacks — using hands-on labs to build strong detection and response capabilities.
5. Digital Forensics & Incident Response (DFIR)
Master evidence acquisition, log and disk forensics, and coordinated response workflows to investigate and contain real incidents through practical, investigation-driven labs.
6. Cloud Forensics & AI-Driven Security
Explore modern cloud environments, apply forensic techniques to cloud incidents, and use AI-based detection tools to enhance threat visibility and automated response.
FAQ
Common questions about CCDL1.
Need More Information? Visit our Help Center for detailed articles about the CCDL1 certification, exam preparation, and more.
Learn the SOC skills that get you hired
Join thousands who've launched their careers and built real SOC muscle


