Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Medium Hard140 hours

SOC Analyst L2

Step up from Tier-1 triage to Tier-2 depth: correlate across sources, hunt on a hypothesis, engineer and tune detections, and lead complex investigations. Recommended after completing SOC Analyst L1.

Recommended first:SOC Analyst L1
Log AnalysisSIEM OperationThreat HuntingDetection EngineeringWindows SecurityNetwork AnalysisIOC AnalysisThreat IntelligenceIncident TriageAnalyst Reporting

What you will be able to do

  • Correlate events across authentication, SIEM, endpoint and proxy sources into one defensible narrative.
  • Reconstruct an accurate, clock-corrected timeline and reason about sequence and causality.
  • Pivot on normalised fields to follow an entity across many log sources at scale.
  • Separate a real multi-stage intrusion from coincidental, unrelated noise.

Units

  1. 01

    Advanced Log Analysis & Correlation

    Move beyond reading one log at a time: correlate across sources, rebuild an accurate timeline, and pivot on normalised fields to see a whole intrusion instead of scattered events.

    Job-ReadyAvailable

    Why you are learning this

    A Tier-2 analyst is handed the cases Tier-1 could not close alone. Those cases are almost never visible in one source — they only appear when authentication, endpoint, SIEM and network logs are read together. Correlation is the core Tier-2 skill. (SOC Analyst L1 is the recommended background for this path.)

    Unit contents9
  2. 02

    Threat Hunting Methodology

    Hunt what no alert caught: form a falsifiable hypothesis, pivot and correlate, weigh competing explanations, judge confidence, and turn each hunt into a detection.

    Job-ReadyAvailable

    Why you are learning this

    Detection rules only catch known techniques; skilled adversaries live in the gaps between them. Proactive, hypothesis-driven hunting is how a Tier-2 team finds the intrusion no alert fired on — and closes the gap by turning the find into a rule. (SOC Analyst L1 remains the recommended background.)

    Unit contents8
  3. 03

    Endpoint Deep-Dive & Host Forensics

    Read one host to the bottom: process ancestry and command lines, the persistence surfaces where attackers hide, and a clock-corrected host timeline that turns scattered artefacts into one intrusion story.

    Job-ReadyAvailable

    Why you are learning this

    Most of what a SOC investigates is host behaviour, and Tier-2 is where the endpoint is read deeply — not 'is this process bad?' but 'who launched it, what did it run, and how did it survive?'. This depth is the foundation for engineering detections and hunting later in the path.

    Unit contents8
  4. 04

    Network Forensics & Traffic Analysis

    Read the other half of every intrusion — the wire. Flows vs full packets, beaconing and C2 by behaviour over content, DNS as a covert channel, exfiltration, and correlating each network finding back to the host that owns it.

    Job-ReadyAvailable

    Why you are learning this

    Half of every modern intrusion — command-and-control and exfiltration — happens on the network, and almost all of it is encrypted. A Tier-2 analyst who can read behaviour and metadata rather than payload finds C2 that content inspection is blind to, and ties the wire signal back to an accountable host. This builds directly on the endpoint depth of Module 3.

    Unit contents8
  5. 05

    Malware Behavioral Triage

    Judge a suspicious sample by what it does, not what it is made of. Read a detonation report as a chain of actions, extract durable indicators via the Pyramid of Pain, classify capability and severity, and decide a proportionate, evidence-preserving response.

    Job-ReadyAvailable

    Why you are learning this

    Static signatures miss anything repacked or new, so Tier-2 triages malware by behaviour — reading a detonation report to name capability, extracting the indicators that scope an incident across the estate, and deciding a response proportionate to the asset. This turns the host and network evidence of Modules 3–4 into a verdict on the payload itself.

    Unit contents8
  6. 06

    Threat Intelligence

    Turn indicators into decisions. Tell intelligence from a raw feed, read the adversary through TTPs and the Diamond Model, judge attribution against false flags, and operationalise it — enrichment, priority requirements, and feeding the next hunt and detection.

    Job-ReadyAvailable

    Why you are learning this

    A SOC drowns in feeds; the Tier-2 skill is turning the right data into a decision — which alert to prioritise, which actor to prepare for, which hunt to run. This module takes the sample and IOCs of Module 5 into the wider adversary landscape and hands a confirmed TTP straight to detection engineering.

    Unit contents8
  7. 07

    Detection Engineering

    Turn a confirmed behaviour into a reliable rule. Target the TTP not the indicator, balance precision against recall, and write, test, tune and maintain detections that catch the technique without drowning the SOC in false positives.

    Job-ReadyAvailable

    Why you are learning this

    Analysts do not scale; detections do. Detection engineering is where a confirmed TTP — handed over by threat intelligence — becomes lasting defensive value: a durable, precise, tested and maintained rule that catches the technique automatically forever after. It takes the intelligence output of Module 6 and produces the rules the whole SOC runs on.

    Unit contents8
  8. 08

    Applied Hunting

    Hunt what no rule catches. Frame a falsifiable hypothesis, search at scale with stack counting and least-frequency analysis, judge rare outliers by context, and close the loop — turning each confirmed hunt into a new detection.

    Job-ReadyAvailable

    Why you are learning this

    Detections only catch techniques someone already knew to write a rule for; capable adversaries live in the gaps. Applied hunting is how a Tier-2 team proactively finds the intrusion that never tripped an alert, at the scale of millions of events — and every successful hunt closes a gap by becoming a detection (Module 7), while a live find escalates into incident response (Module 9).

    Unit contents8
  9. 09

    Incident Response

    Run a confirmed intrusion from declaration to closure. Work the lifecycle in order — contain before eradicate, scope before eradicate, validate before closing — preserve evidence, remove every foothold, recover with verification, and close with a lessons-learned report.

    Job-ReadyAvailable

    Why you are learning this

    When a hunt or triage confirms a real intrusion, someone has to run the response — and doing it in the wrong order destroys evidence, misses scope, and re-infects. Tier-2 analysts drive incidents through the lifecycle under pressure without those mistakes, and the lessons-learned phase feeds new detections (Module 7) and hunts (Module 8), closing the operational loop.

    Unit contents8
  10. 10

    Integrated Operations

    Run the whole SOC as one system. Move a single case fluidly through correlation, hunting, detection and response; prioritise a full queue by risk; escalate what matters; and hold it together with clean handovers, communication and a continuous-improvement loop.

    Job-ReadyAvailable

    Why you are learning this

    Real cases do not arrive labelled by discipline, and there are always more alerts than analysts. Tier-2 analysts run the whole workflow on one case — correlate, hunt, detect, respond — prioritise the queue by risk, escalate early, and keep the operation coherent across shifts. This module ties Modules 1–9 into one operation and sets up the Capstone.

    Unit contents9

Recommended next