SOC Analyst Training & Certification - CCDL1
The industry's most practical blue team certification for aspiring SOC Analysts. Learn to detect, investigate, and respond to cyber attacks through real-world investigations.
Key Features
Real-World Readiness
Train SOC analysts with real cyber incident simulations.
Job-Ready Skills
Developed with Mandiant & PwC SOC Managers to build the skills they hire for.
Industry Aligned
90% aligned with NIST Cyber Defense Analyst role.
Modern & Evolving Content
Up-to-date SOC training with AI, AWS, and Azure Sentinel labs
Trusted by Defenders Across Leading Organizations

Who is it for?
CCDL1 builds the practical skills to perform as a Tier 1 SOC analyst. It's designed for:
Students
In CS, IT, or cybersecurity preparing to land their first SOC role.
IT Professionals
Developers, sysadmins, help desk, and more breaking into defensive security.
Associate SOC Analysts
Building core investigation, detection, and response skills.
Prerequisites
Recommended experience:
- Windows and Linux fundamentals
- Basic command-line usage
- General networking knowledge
What You'll Learn
Skills you'll validate with CCDL1:
Operate in a SOC
Perform end-to-end SOC workflows including detection, triage, escalation, and reporting
Master SIEM Operations
Use SIEM tools like Microsoft Sentinel to detect, investigate, and visualize threats.
Investigate Security Alerts
Correlate multi-source logs to detect, validate, and prioritize real cyber incidents.
Conduct Digital Forensics
Acquire, preserve, and analyze digital evidence to trace attacker activities.
Respond to Incidents
Contain, eradicate, and recover from security breaches through structured IR processes.
Build Confidence
Apply your SOC skills to investigate and respond to real cyber incidents.
Prepare for the Exam
1. Phishing & Email Security
Identify and analyze phishing attempts, spoofing, and business email compromise (BEC) attacks, using hands-on labs to build strong detection and response capabilities.
2. Network Fundamentals & Threat Detection
Learn how to protect enterprise infrastructure by monitoring network traffic, detecting intrusions, and securing endpoints and Active Directory against malware, exploits, and lateral movement.
3. SIEM Operations
Gain hands-on experience collecting and correlating logs in Splunk, writing SPL searches, building alerts and dashboards, and working through real threat hunting cases like a SOC analyst.
4. Digital Forensics & Incident Response (DFIR)
Master evidence acquisition and Windows forensics, from registry and file system artifacts to memory analysis, and build timelines that reconstruct exactly what happened during an incident.
5. Cloud Security
Explore Azure environments, analyze cloud logs with KQL, and investigate real cloud attacks, from suspicious sign-ins to application abuse and exposed storage.
6. SOC Decision Method
Bring it all together with a structured decision process for real incidents, taking an alert from first triage all the way to a clear, complete handover.
FAQ
Common questions about CCDL1.
Need More Information? Visit our Help Center for detailed articles about the CCDL1 certification, exam preparation, and more.
Learn the SOC skills that get you hired
Join thousands who've launched their careers and built real SOC muscle


