← All trainingCourse in Guardian Foundry
Virtual SOC Tier 2
Work through escalated alerts in a simulated SOC environment. Investigate malicious DNS, unusual user activity, network anomalies and endpoint malware detections using the evidence available in each case.
What you’ll practice
- Triage escalated alerts and identify the evidence needed for an investigation.
- Investigate suspicious user activity, network behavior and endpoint detections.
- Correlate case evidence to reach and explain an alert disposition.
Topics
- SOC analysis
- Incident response
Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.