top of page
EC-Council SOC Essentials

EC-Council SOC Essentials

Course Code

Duration

ECC-SOC

2 days

About the Course

The SOC Essentials (SCE) is designed for aspiring security professionals, freshers, and career switchers to provide insights into security operations frameworks and related technologies. With 8 modules covering robust topics from the computer network and security fundamentals to SOC components and architecture, SCE prepares you to identify various aspects of cyber threats and secure digital environments. No IT/cybersecurity experience is required for this course. Test your skills with CTF-based Capstone Project and validate these newly acquired skills in proctored exams.


Skills you'll learn with the SOC Essentials program


  • Learn the basics of computer network.

  • Dive deep into the cyber threat concepts like threats, vulnerabilities, and attacks.

  • Gain insights into the Security Operations Center (SOC) architecture and learn the importance, workflows, and processes of SOC.

  • Understand advanced architectural concepts like SIEM architecture and deployment models.

  • Learn what log management is and its key parts, like events, logs, and incidents.

  • Learn how you can performace centralized management of logs.

  • Gain knowledge on dashboards, reports, and incident escalation in terms of dealing with real positive and false alerts.

  • Discover the sources, types, and lifecycle of threat intelligence and get introduced to threat hunting.

  • Deep dive into the incident response lifecycle.


Target Audience


  • High school students, college, and university students.

  • IT, technology, cybersecurity teams with little or no work experience.

  • Anyone who wants to start a career in cybersecurity and is interested in SOC.

  • This course is also helpful for IT professionals, SOC analysts, system security professionals, security engineers, threat management professionals, incident response teams, security administrators, vulnerability management professionals, and any cybersecurity professionals.


Course Outline


Module 1: Computer Network and Security Fundamentals

  • TCP/IP model.

  • OSI model.

  • Types of a network.

  • Network topologies.

  • Network hardware components.

  • TCP/IP protocol suite.

  • Network security controls.

  • Network security devices.

  • Windows security.

  • Unix/Linux security.

  • Web application fundamentals.

  • Information security standards, laws and acts.


Module 2: Fundamentals of Cyber Threats

  • Cyber threats.

  • Intent-motive-goal.

  • Tactics-techniques-procedures.

  • Opportunity-vulnerability-weaknesses.

  • Vulnerability.

  • Threats and attacks.

  • Example of attacks.

  • Network-based attacks.

  • Application-based attacks.

  • Host-based attacks.

  • Insider attacks.

  • Malware.

  • Phishing and social engineering.


Module 3: Introduction to Security Operations Center

  • What is Security Operations Center (SOC)?

  • Importance of SOC.

  • SOC team roles and responsibilities.

  • SOC KPI.

  • SOC metrics.

  • SOC maturity models.

  • SOC workflows and processes.

  • Challenges in operating a SOC.


Module 4: SOC Components and Architecture

  • Key components of a SOC.

  • People in SOC.

  • Process in SOC.

  • Technologies in SOC.

  • SOC architecture and infrastructure.

  • Different types of SOCs and their purposes.

  • Introduction to SIEM.

  • SIEM architecture.

  • SIEM deployment models.

  • Data sources in SIEM.

  • SIEM logs.

  • Network in SIEM.

  • Endpoint data in SIEM.


Module 5: Introduction to Log Management

  • Incident.

  • Event.

  • Log.

  • Typical log sources.

  • Need of log.

  • Typical log format.

  • Local local management.

  • Centralized log management.

  • Logging best practices.

  • Logging/log management tools.


Module 6: Incident Detection and Analysis

  • SIEM and use case development.

  • Security monitoring and analysis.

  • Correlation rules.

  • Dashboards.

  • Reports.

  • Alerting.

  • Triaging alerts.

  • Dealing with false positives and alerts.

  • Incident escalation.

  • Communication paths.

  • Ticketing systems.


Module 7: Threat Intelligence and Hunting

  • Introduction to threat intelligence.

  • Threat intelligence sources.

  • Threat intelligence types.

  • Threat intelligence lifecycle.

  • Role of threat intelligence in SOC operations.

  • Threat intelligence feeds.

  • Threat intelligence sharing and collaboration.

  • Threat intelligence tools/platforms.

  • Introduction to threat hunting.

  • Threat hunting techniques.

  • Threat hunting methodologies.

  • Role of threat hunting in SOC operations.

  • Leveraging threat intelligence for hunting.

  • Threat hunting tools.


Module 8: Incident Response and Handling

  • Incident handling process.

  • Incident classification and prioritization.

  • Incident response lifecycle.

  • Preparation.

  • Identification

  • Containment.

  • Eradication.

  • Recovery.

  • Post-incident analysis and reporting.


Exam Details


Pre-requisite: No prior cybersecurity knowledge or IT work experience required.

Exam code: 112-56

Number of questions: 75

Duration: 2 hours

Test format: Multiple choice


Please contact us to schedule your exam, book a private corporate training, or join a public schedule.



bottom of page