← All trainingCourse in Guardian Foundry

SOC Analyst Tier 2 Triage

Go deeper into Windows internals, compromised-host investigations and threat hunting in ELK. Examine memory, persistence and log evidence, then document findings in DFIR and threat hunt reports.

What you’ll practice

  • Use Windows architecture and memory concepts to investigate a compromised host.
  • Build and test threat hunt queries using logs, baselines and time context.
  • Write DFIR and threat hunt reports that connect conclusions to evidence.

Topics

  • SOC analysis
  • Digital forensics
  • Threat hunting

Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.

Talk to Rob or Anthony

Plan your team’s training.

Tell us how many people you’re training, their experience levels, and what they need to practice. We’ll discuss a training plan, learner support, and the reporting your team needs.

info@leveleffect.com
Email the team

We aim to respond within 1–2 business days.