Bristleback SOC analyst mascot investigating a security case

BRISTLEBACK SECURITY OPERATIONS BBSOC · ADVANCED PROGRAM

Learn to detect threats.
Investigate how attacks unfold.

Build practical security-operations skills through monitoring, SIEM investigation, threat hunting, digital forensics, incident response and realistic SOC simulations.

18Modules
4Levels
LabsPractical work
SOCSimulation

02 · THE RIGHT FOUNDATION

Build the capability behind the alerts.

BBSOC takes you from cybersecurity and SOC fundamentals to full incident investigation, threat hunting, detection engineering and professional reporting.

01
◎

What you'll learn

Security monitoring, SIEM, network detection, phishing analysis, endpoint investigation, DFIR, malware analysis, threat hunting, incident response and detection engineering.

02
◌

Who is this for?

Aspiring SOC analysts, cybersecurity learners, IT and system administrators, network professionals and anyone building a practical blue-team career.

03
⌁

Prerequisites

Basic computer, networking and operating-system knowledge is recommended. Foundation programs are available if you need to strengthen the fundamentals.

Explore foundations →

03 · THE BBSOC PATH

From security foundations to full SOC simulation.

A four-level progression from monitoring and detection to investigation, response and advanced defensive operations.

LEVEL 1

Cybersecurity & SOC Foundations

01Cybersecurity Fundamentals8 topics+
  • CIA triad
  • Threats, vulnerabilities, risks
  • Security controls
  • Authentication & authorization
  • Defense in depth
  • Common attack types
  • Cyber Kill Chain
  • MITRE ATT&CK introduction
02Networking for SOC Analysts12 topics+
  • OSI & TCP/IP
  • IP addressing
  • TCP/UDP
  • DNS
  • DHCP
  • HTTP/HTTPS
  • SMTP
  • SSH
  • SMB
  • LDAP
  • Kerberos
  • Common network attacks
03Windows & Linux Security Fundamentals10 topics+
  • Windows architecture
  • Linux architecture
  • Users & groups
  • Processes & services
  • File permissions
  • Windows Registry
  • PowerShell
  • Linux shell
  • Authentication
  • Security logs
04SOC Fundamentals11 topics+
  • What is a SOC?
  • SOC architecture
  • SOC roles: L1/L2/L3
  • SOC workflow
  • Alert → Triage → Investigation → Escalation
  • SIEM
  • EDR/XDR
  • IDS/IPS
  • Firewall
  • SOAR
  • SOC metrics
LEVEL 2

Security Monitoring & Threat Detection

05Log Management & Analysis10 topics+
  • Windows Event Logs
  • Sysmon
  • Linux logs
  • Authentication logs
  • Firewall logs
  • DNS logs
  • Web server logs
  • Log collection
  • Log normalization
  • Timeline analysis
06SIEM & Security Operations12 topics+
  • SIEM architecture
  • Log ingestion
  • Searching
  • Correlation
  • Dashboards
  • Alerts
  • Investigation
  • Detection rules
  • Splunk
  • Wazuh
  • Basic SPL
  • SIEM-based investigations
07Network Security Monitoring11 topics+
  • Packet analysis
  • Wireshark
  • tcpdump
  • Network flows
  • DNS analysis
  • HTTP analysis
  • Suspicious traffic
  • Port scanning
  • Brute force
  • C2 traffic
  • PCAP investigation
08IDS/IPS & Network Detection9 topics+
  • IDS vs IPS
  • Signature vs anomaly detection
  • Snort
  • Suricata
  • Zeek
  • Detection rules
  • Alert analysis
  • Rule tuning
  • Integrating network alerts with SIEM
LEVEL 3

Investigation, DFIR & Threat Hunting

09Phishing & Threat Intelligence12 topics+
  • Email security
  • Email header analysis
  • SPF/DKIM/DMARC
  • Malicious URLs
  • Malicious attachments
  • IOC
  • IOA
  • TTP
  • Threat intelligence lifecycle
  • IOC enrichment
  • MITRE ATT&CK
  • Threat intelligence tools
10Endpoint Security & Investigation14 topics+
  • Endpoint security concepts
  • EDR concepts
  • Windows investigation
  • Processes
  • Services
  • Scheduled tasks
  • PowerShell
  • WMI
  • Persistence
  • Linux investigation
  • SSH
  • Cron
  • Authentication
  • Endpoint telemetry
11Digital Forensics14 topics+
  • Digital forensics fundamentals
  • Evidence handling
  • Forensic imaging
  • Hashing
  • File-system investigation
  • Windows artifacts
  • Registry
  • Browser artifacts
  • Event logs
  • Timeline analysis
  • Memory forensics
  • Autopsy
  • FTK Imager
  • Volatility
12Malware Analysis Fundamentals13 topics+
  • Malware types
  • Malware lifecycle
  • Static analysis
  • Dynamic analysis
  • File hashes
  • Strings
  • PE basics
  • Processes
  • Registry changes
  • Network behaviour
  • Sandbox analysis
  • IOC extraction
  • YARA
13Threat Hunting11 topics+
  • Threat hunting concepts
  • Hunting methodology
  • Hypothesis-driven hunting
  • IOC hunting
  • TTP hunting
  • MITRE ATT&CK hunting
  • SIEM hunting
  • Network hunting
  • Endpoint hunting
  • SPL
  • KQL fundamentals
LEVEL 4

Incident Response & Advanced SOC

14Incident Response11 topics+
  • Incident response lifecycle
  • Preparation
  • Identification
  • Containment
  • Eradication
  • Recovery
  • Lessons learned
  • Incident classification
  • Incident prioritization
  • Evidence preservation
  • Root-cause analysis
15Common Incident Investigations10 topics+
  • Phishing attack
  • Credential compromise
  • Brute-force attack
  • Malware infection
  • Ransomware
  • PowerShell attack
  • Web server compromise
  • Insider threat
  • Data exfiltration
  • Active Directory compromise
16Detection Engineering12 topics+
  • Detection engineering fundamentals
  • Detection logic
  • Indicators vs behaviours
  • SIEM correlation
  • Detection rules
  • Sigma
  • YARA
  • Alert tuning
  • False positives
  • Detection coverage
  • MITRE ATT&CK mapping
  • Detection lifecycle
17SOC Reporting & Communication10 topics+
  • Analyst notes
  • Incident timeline
  • Evidence documentation
  • IOC documentation
  • Technical incident report
  • Executive summary
  • Root cause
  • Business impact
  • Remediation
  • Incident presentation
18Full SOC Simulation / Capstone10 topics+
  • End-to-end SOC investigation
  • Alert triage
  • Evidence correlation
  • Threat identification
  • Containment decisions
  • Incident documentation
  • Detection improvement
  • Final incident report
  • Analyst communication
  • Capstone review

04 · PRACTICAL SOC WORK

Don't just operate security tools. Learn to reason from evidence.

Practice the workflow analysts use: identify what matters, correlate evidence, investigate the story behind an alert and communicate what happened.

>_

Alert Triage

Decide what deserves attention and why.

>_

Log Investigation

Correlate events across hosts, users and services.

>_

Network Detection

Read packets, flows, DNS and suspicious traffic.

>_

Endpoint Investigation

Trace processes, persistence and system activity.

>_

Threat Hunting

Search for behaviours and indicators beyond alerts.

>_

Incident Response

Contain, document and communicate a complete incident.

05 · PRICING

BBSOC course fee.

The standard BBSOC course fee is ₹35,000. Learning-mode offers are calculated automatically from the standard fee. The course fee is collected in two equal instalments.

FULL COURSE FEE

₹35,000

Standard fee for the complete BBSOC programme.

Full price
ONLINE · 40% OFF

₹21,000

Save ₹14,000 · 2 equal instalments of ₹10,500

Online offer
OFFLINE · 10% OFF

₹31,500

Save ₹3,500 · 2 equal instalments of ₹15,750

Offline offer
Two equal instalments.Registration Open · Batch allocation is confirmed before payment and course commencement.₹35,000 standard

REFUND & CANCELLATION

Four Learning Satisfaction Checkpoints. You stay in control.

The course fee for the selected learning mode is collected in two equal instalments. At 25%, 50%, 75% and 100% of syllabus coverage, you can assess whether the learning delivered so far is satisfactory. If you are not satisfied, the applicable Learning Satisfaction Checkpoint refund is available and you may exit. No certificate is issued for an unsatisfied exit.

25% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of 1st instalment

Exit the programme. No certificate is issued.

50% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of 1st instalment

Exit the programme. If satisfied, pay the 2nd instalment and continue.

75% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of 2nd instalment

Exit the programme. No certificate is issued.

100% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of 2nd instalment

Exit the programme. If satisfied, the programme is completed and a Certificate of Completion is issued.

Two instalments · four Learning Satisfaction Checkpoints.The checkpoint refund is calculated against the relevant equal instalment of the selected learning mode. See the full Refund & Cancellation Policy for complete terms and examples.

06 · CHOOSE HOW YOU LEARN

Learn online. Learn in the classroom.

Choose the mode that fits you. Batch availability depends on learner demand and confirmed scheduling.

Teaching languages: English and Tamil.

01

Online

Live online learning with instructor-led sessions, guided investigations and practical SOC work.

02

Offline

Classroom learning in Puducherry when an offline batch is confirmed.

03

Flexible

Prefer either mode? Tell us during registration and we will consider you for the next suitable batch.

07 · BATCH AVAILABILITY

Find a learning slot that works for you.

No BBSOC batch has been confirmed yet. Current slots remain open for allocation based on learner demand.

SLOT 01Awaiting allocationNo batch assigned yet
SLOT 02Launching SoonBBSOC
SLOT 03Awaiting allocationNo batch assigned yet
SLOT 04Awaiting allocationNo batch assigned yet

08 · CERTIFICATION & REGISTRATION

Ready to start BBSOC?

Register your interest, tell us your preferred learning mode and schedule, and we'll consider you for the next suitable batch. Payment is collected only after your batch is confirmed.

BBSOC Certificate of Completion

Complete the programme requirements and practical learning journey to receive the Bristleback Security Operations & Cyber Defense Certificate of Completion.

Register Today →