Skip to Content

EC-Council Certified SOC Analyst (CSA)

The Certified SOC Analyst (CSA) program is the first step to joining a Security Operations Center (SOC). It is designed for current and future Level I and Level II SOC analysts to acquire skills in executing entry-level and intermediate-level operations.

CSA is a training and accreditation program that helps the candidate acquire trending and sought-after technical skills through instruction from some of the most experienced trainers in the industry. The program focuses on creating new career opportunities through in-depth and meticulous knowledge with enhanced level capabilities to dynamically contribute to a SOC team. Being an intense 3-day program, it covers in detail the fundamentals of SOC operations, before relaying knowledge on log management and correlation, SIEM deployment, advanced incident detection, and incident response. Additionally, the candidate will learn to manage various SOC processes and collaborate with the CSIRT as needed.

0.000 DT 0.000 DT
  • SOC Analysts (Level I and Level II)
  • Network and security administrators, network and security engineers, network defense analysts, network defense technicians, network security specialists, network security operators, and any security professional responsible for network security operations
  • Cybersecurity Analyst
  • Entry-level cybersecurity professionals
  • Anyone wishing to become a SOC analyst.

Le programme Certified SOC Analyst (CSA) est la première étape pour rejoindre un centre d’opérations de sécurité (SOC). Il est conçu pour les analystes SOC actuels et futurs de niveau I et de niveau II afin d’acquérir des compétences dans l’exécution d’opérations de niveau d’entrée et de niveau intermédiaire.

CSA est un programme de formation et d’accréditation qui aide le candidat à acquérir des compétences techniques tendances et recherchées grâce à l’enseignement de certains des formateurs les plus expérimentés de l’industrie. Le programme se concentre sur la création de nouvelles opportunités de carrière grâce à des connaissances approfondies et méticuleuses avec des capacités de niveau améliorées pour contribuer de manière dynamique à une équipe SOC. S’agissant d’un programme intense de 3 jours, il couvre en détail les principes fondamentaux des opérations SOC, avant de relayer les connaissances sur la gestion et la corrélation des journaux, le déploiement SIEM, la détection avancée des incidents et la réponse aux incidents. De plus, le candidat apprendra à gérer divers processus SOC et à collaborer avec le CSIRT en cas de besoin.

As the security landscape evolves, a SOC team offers high-quality cybersecurity services to actively detect potential cyber threats/attacks and respond quickly to security incidents. Organizations need qualified SOC analysts who can serve as frontline defenders, alerting other professionals to emerging and current cyber threats.

The intensive lab CSA program emphasizes a holistic approach to providing foundational and advanced knowledge on how to identify and validate intrusion attempts. Through this, the candidate will learn to use SIEM solutions and predictive capabilities with the help of threat intelligence. The program also introduces the practical aspect of SIEM using advanced and most commonly used tools. The candidate will learn to perform enhanced threat detection using the predictive capabilities of Threat Intelligence.

Recent years have seen the evolution of cyber risks, creating an unsafe environment for actors in various sectors.

To address these sophisticated threats, companies need advanced cybersecurity solutions as well as traditional defense methods. Practicing good cybersecurity hygiene and establishing an appropriate line of defense, and integrating a security operations center (SOC) have become reasonable solutions. The team maintains 24/7 coverage and "follows the sun" to carry out security monitoring, security incident management, vulnerability management, security device management, and network flow monitoring.

A SOC analyst continuously monitors and detects potential threats, sorts alerts, and escalates them appropriately. Without a SOC analyst, processes such as monitoring, detection, analysis, and sorting will lose their effectiveness, which will ultimately have a negative impact on the organization.

  • Module 01 : Security Operations and Management
  • Module 02 : Understanding Cyber Threats, IoCs, and Attack Methodology
  • Module 03 : Incidents, Events, and Logging
  • Module 04 : Incident Detection with Security Information and Event Management (SIEM)
  • Module 05 : Enhanced Incident Detection with Threat Intelligence
  • Module 06 : Incident Response