SOC Analyst L2
Step up from Tier-1 triage to Tier-2 depth: correlate across sources, hunt on a hypothesis, engineer and tune detections, and lead complex investigations. Recommended after completing SOC Analyst L1.
What you will be able to do
- Correlate events across authentication, SIEM, endpoint and proxy sources into one defensible narrative.
- Reconstruct an accurate, clock-corrected timeline and reason about sequence and causality.
- Pivot on normalised fields to follow an entity across many log sources at scale.
- Separate a real multi-stage intrusion from coincidental, unrelated noise.
Units
- 01
Advanced Log Analysis & Correlation
Move beyond reading one log at a time: correlate across sources, rebuild an accurate timeline, and pivot on normalised fields to see a whole intrusion instead of scattered events.
Job-ReadyAvailableWhy you are learning this
A Tier-2 analyst is handed the cases Tier-1 could not close alone. Those cases are almost never visible in one source — they only appear when authentication, endpoint, SIEM and network logs are read together. Correlation is the core Tier-2 skill. (SOC Analyst L1 is the recommended background for this path.)
Unit contents9
Theory Lessons(4)
Practical Labs(5)
Correlating a Multi-Source Intrusion
Browser Lab+130 XPThe Cross-Source Correlation Case
Investigation+220 XPModule 1 Assessment — Part B: Correlate and Decide
Assessment+240 XPModule 1 Assessment — Part A: Correlation Knowledge
Assessment+200 XPModule 10 Assessment — Part A: Integrated Operations
Assessment+200 XP
- 02
Threat Hunting Methodology
Hunt what no alert caught: form a falsifiable hypothesis, pivot and correlate, weigh competing explanations, judge confidence, and turn each hunt into a detection.
Job-ReadyAvailableWhy you are learning this
Detection rules only catch known techniques; skilled adversaries live in the gaps between them. Proactive, hypothesis-driven hunting is how a Tier-2 team finds the intrusion no alert fired on — and closes the gap by turning the find into a rule. (SOC Analyst L1 remains the recommended background.)
Unit contents8
Theory Lessons(4)
Practical Labs(4)
- 03
Endpoint Deep-Dive & Host Forensics
Read one host to the bottom: process ancestry and command lines, the persistence surfaces where attackers hide, and a clock-corrected host timeline that turns scattered artefacts into one intrusion story.
Job-ReadyAvailableWhy you are learning this
Most of what a SOC investigates is host behaviour, and Tier-2 is where the endpoint is read deeply — not 'is this process bad?' but 'who launched it, what did it run, and how did it survive?'. This depth is the foundation for engineering detections and hunting later in the path.
Unit contents8
Theory Lessons(4)
Practical Labs(4)
- 04
Network Forensics & Traffic Analysis
Read the other half of every intrusion — the wire. Flows vs full packets, beaconing and C2 by behaviour over content, DNS as a covert channel, exfiltration, and correlating each network finding back to the host that owns it.
Job-ReadyAvailableWhy you are learning this
Half of every modern intrusion — command-and-control and exfiltration — happens on the network, and almost all of it is encrypted. A Tier-2 analyst who can read behaviour and metadata rather than payload finds C2 that content inspection is blind to, and ties the wire signal back to an accountable host. This builds directly on the endpoint depth of Module 3.
Unit contents8
Theory Lessons(4)
Practical Labs(4)
- 05
Malware Behavioral Triage
Judge a suspicious sample by what it does, not what it is made of. Read a detonation report as a chain of actions, extract durable indicators via the Pyramid of Pain, classify capability and severity, and decide a proportionate, evidence-preserving response.
Job-ReadyAvailableWhy you are learning this
Static signatures miss anything repacked or new, so Tier-2 triages malware by behaviour — reading a detonation report to name capability, extracting the indicators that scope an incident across the estate, and deciding a response proportionate to the asset. This turns the host and network evidence of Modules 3–4 into a verdict on the payload itself.
Unit contents8
Theory Lessons(4)
Practical Labs(4)
- 06
Threat Intelligence
Turn indicators into decisions. Tell intelligence from a raw feed, read the adversary through TTPs and the Diamond Model, judge attribution against false flags, and operationalise it — enrichment, priority requirements, and feeding the next hunt and detection.
Job-ReadyAvailableWhy you are learning this
A SOC drowns in feeds; the Tier-2 skill is turning the right data into a decision — which alert to prioritise, which actor to prepare for, which hunt to run. This module takes the sample and IOCs of Module 5 into the wider adversary landscape and hands a confirmed TTP straight to detection engineering.
Unit contents8
Theory Lessons(4)
From Data to Decision: What Threat Intelligence Is (and Isn't)
Theory+70 XPReading the Adversary: TTPs, the Diamond Model and Attribution
Theory+70 XPOperationalising Intelligence: Enrichment, Requirements and Feeding Detection
Theory+70 XPModule 6 Knowledge Check — Threat Intelligence
Knowledge Check+90 XP
Practical Labs(4)
- 07
Detection Engineering
Turn a confirmed behaviour into a reliable rule. Target the TTP not the indicator, balance precision against recall, and write, test, tune and maintain detections that catch the technique without drowning the SOC in false positives.
Job-ReadyAvailableWhy you are learning this
Analysts do not scale; detections do. Detection engineering is where a confirmed TTP — handed over by threat intelligence — becomes lasting defensive value: a durable, precise, tested and maintained rule that catches the technique automatically forever after. It takes the intelligence output of Module 6 and produces the rules the whole SOC runs on.
Unit contents8
Theory Lessons(4)
Practical Labs(4)
- 08
Applied Hunting
Hunt what no rule catches. Frame a falsifiable hypothesis, search at scale with stack counting and least-frequency analysis, judge rare outliers by context, and close the loop — turning each confirmed hunt into a new detection.
Job-ReadyAvailableWhy you are learning this
Detections only catch techniques someone already knew to write a rule for; capable adversaries live in the gaps. Applied hunting is how a Tier-2 team proactively finds the intrusion that never tripped an alert, at the scale of millions of events — and every successful hunt closes a gap by becoming a detection (Module 7), while a live find escalates into incident response (Module 9).
Unit contents8
Theory Lessons(4)
Practical Labs(4)
- 09
Incident Response
Run a confirmed intrusion from declaration to closure. Work the lifecycle in order — contain before eradicate, scope before eradicate, validate before closing — preserve evidence, remove every foothold, recover with verification, and close with a lessons-learned report.
Job-ReadyAvailableWhy you are learning this
When a hunt or triage confirms a real intrusion, someone has to run the response — and doing it in the wrong order destroys evidence, misses scope, and re-infects. Tier-2 analysts drive incidents through the lifecycle under pressure without those mistakes, and the lessons-learned phase feeds new detections (Module 7) and hunts (Module 8), closing the operational loop.
Unit contents8
Theory Lessons(4)
Practical Labs(4)
- 10
Integrated Operations
Run the whole SOC as one system. Move a single case fluidly through correlation, hunting, detection and response; prioritise a full queue by risk; escalate what matters; and hold it together with clean handovers, communication and a continuous-improvement loop.
Job-ReadyAvailableWhy you are learning this
Real cases do not arrive labelled by discipline, and there are always more alerts than analysts. Tier-2 analysts run the whole workflow on one case — correlate, hunt, detect, respond — prioritise the queue by risk, escalate early, and keep the operation coherent across shifts. This module ties Modules 1–9 into one operation and sets up the Capstone.
Unit contents9
Theory Lessons(4)
Practical Labs(5)
Run One Case Through the Whole Workflow
Browser Lab+130 XPOperate the Floor: One Shift, One System
Investigation+220 XPThe Full Integrated Shift: One Incident, Every Discipline
Boss LabJob Simulation+500 XPModule 10 Assessment — Part B: Operate the Floor
Assessment+240 XPModule 10 Assessment — Part A: Integrated Operations
Assessment+200 XP
Recommended next
Incident Response
Move from a confirmed alert into structured response: validate, scope, preserve evidence, contain, eradicate, recover — and report to both engineers and executives. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
Threat Hunting
Proactive, hypothesis-driven investigation — finding attacker behavior the alerts missed, and turning what you find into new detections. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.