← All trainingCourse in Guardian Foundry
SOC Analyst Tier 2 Triage
Go deeper into Windows internals, compromised-host investigations and threat hunting in ELK. Examine memory, persistence and log evidence, then document findings in DFIR and threat hunt reports.
What you’ll practice
- Use Windows architecture and memory concepts to investigate a compromised host.
- Build and test threat hunt queries using logs, baselines and time context.
- Write DFIR and threat hunt reports that connect conclusions to evidence.
Topics
- SOC analysis
- Digital forensics
- Threat hunting
Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.