CyBe AI Summit 2026 — NIMHANS Convention Centre, Bengaluru — 4 Sep 2026Learn more
AISA·Intermediate

AI SOC Analyst: Weekend Cohort

Six Saturday mornings. Both sides of the AI shift — the attacks and the tooling — investigated end to end on real enterprise consoles.

6 weekends

Saturdays, 10:30–13:30

47 lessons

Full lab course included, 3 months

18 CISOs

Curriculum reviewed by

100%

Hands-on, no slideware

Maps to the domains of

MicrosoftSC-200
EC-CouncilEC-Council CSA
CompTIACySA+
₹24,500₹41,000

40% off the release price. Includes 3 months of lab access, and certification with 2 attempts (worth ₹10,000) free with the full cohort. Booking single Saturdays instead? Certification can be added to any session for ₹10,000.

Book the Full CohortSee the Full Lab Course

This course includes

  • 5 live sessions plus 1 immersive day, Saturdays 10:30–13:30
  • 3 months of access to the full 40-chapter lab course, including the 72-hour Siege capstone
  • Arcs M3 and M4 taught live in full — every lesson and micro-project
  • Instructor-led cohort, Bangalore or virtual
  • A downloadable incident report from every lesson and micro-project
  • Certification included — 2 attempts within 3 months of finishing
  • Maps to CompTIA Security+, ISC2 CC, and CompTIA SecAI+ domains
  • Cloud labs on real Sentinel, AWS and Azure consoles — no local setup

What You’ll Learn

Investigate AI-generated phishing at scale, and tell an LLM-written campaign from a human-written one on the evidence.
Detect and triage prompt injection against enterprise AI tools — M365 Copilot, Slack AI, ServiceNow Now Assist.
Work a deepfake BEC and a voice-clone vishing case from the artifacts, the way the Arup and Ferrari incidents actually landed.
Hunt across cloud log sources — CloudTrail, Azure Activity Log, VPC Flow — and reconstruct a cloud kill chain.
Trace IAM privilege escalation, S3 exfiltration, and Lambda persistence in a live AWS console.
Write and run detection logic in KQL against Microsoft Sentinel, including a full phishing playbook.
Detect cross-account and cross-cloud lateral movement between AWS and Azure.
Design SOAR playbooks that automate the SOC response instead of adding queue depth.
Map what you find to MITRE ATT&CK and MITRE ATLAS, the AI-specific framework, side by side.

Skills You’ll Gain

Microsoft SentinelKQLAWS CloudTrailAWS IAMAWS S3 ForensicsAWS LambdaAzure Activity LogSentinel UEBASOAR PlaybooksPrompt Injection DetectionDeepfake ForensicsEmail Header AnalysisMITRE ATT&CKMITRE ATLASCopilot for SecurityIncident Reporting

What is taught live, and what is in the lab

Enrolment buys two things. The six Saturdays are instructor-led and cover the AI and cloud half of the syllabus. The same enrolment also opens the full AI SOC Analyst lab course on labs.cybe.global for three months, which is larger than what the live sessions cover and is worked in your own time.

Live instructor sessions

6 Saturdays · 34 lessons

Taught in the room or on the call, with an instructor working the case alongside the cohort. This is the schedule listed below.

  • Arc M3, AI-Era Threat Investigation, in full — AI phishing, prompt injection against Copilot, Slack AI and ServiceNow, deepfake and voice-clone cases, UEBA bypass, adversarial ML
  • Arc M4, AI-Era Cloud SOC, in full — cloud log sources, IAM privilege escalation, S3 exfiltration, Lambda persistence, cross-cloud lateral movement, SOAR automation
  • The 7 foundation lessons from arcs M0 to M2 that M3 and M4 formally require: Linux CLI, log analysis, KQL, incident reporting, AD credential forensics
  • The Cyber War Room immersive day and the certification exam, both on Saturday 28 November
  • The other 20 foundation lessons in arcs M1 and M2 — endpoint triage, YARA, EVTX parsing, threat intel and Sentinel analytics rules — which are in the lab, not the live sessions
  • The 72-hour Siege capstone, which runs self-paced in the lab

Self-paced lab course

3 months · 47 lessons

The complete AI SOC Analyst programme on labs.cybe.global, unchanged and unabridged. Included with enrolment and open for three months from the final Saturday.

  • All 47 lessons across the 5 arcs plus Siege, including every lesson the live sessions do not reach
  • The full 72-hour SOC Siege capstone, graded by practising security leaders
  • 14 micro-projects, each a named real-world case worked from the artifacts
  • 63 portfolio artifacts, mapped across 174 MITRE ATT&CK techniques
  • A live terminal lab environment on real Sentinel, AWS and Azure consoles

The two run on the same continuous 33-day Noowapay breach, so lab chapters worked between Saturdays feed directly into the next live session rather than sitting apart from it.

Curriculum

6 modules · 34 lessons

  • What is a SOC?Preview25 min
  • Your First Shift35 min
  • Linux CLI for SOC Analysts75 min
  • Log Analysis 10150 min

Upcoming cohort dates

One cohort, six Saturday sessions. Half-day sessions run 10:30–13:30; the closing immersive day runs 10:30–17:30. Attend in Bangalore or join virtually.

Bangalore / Virtual

  1. 1Sat 17 OctLive session · 10:30–13:30
  2. 2Sat 24 OctLive session · 10:30–13:30
  3. 3Sat 31 OctLive session · 10:30–13:30
  4. Sat 7 NovDiwali holiday — no session
  5. 4Sat 14 NovLive session · 10:30–13:30
  6. 5Sat 21 NovLive session · 10:30–13:30
  7. 6Sat 28 NovExam dayImmersive day and certification exam · 10:30–17:30

Lab access runs for 3 months. Certification allows 2 attempts within 3 months of the final session.

Individual sessions can also be booked on their own — ₹2,700 for a half-day session, or ₹3,600 for the full-day immersive that includes the Cyber War Room. Follow any date above to book it.

Only need one part of this?

Each Saturday is a self-contained capability — phishing triage, endpoint forensics, cloud and SOAR — and can be booked on its own without joining the cohort. Every session page carries its own labs, ATT&CK coverage and price.

Compare the six sessions

What backs this up

The specifics behind the claims on this page. Open any of them for the detail.

  • Day 0

    Before the Storm

    Analyst onboarding and SOC mission, before any alert fires. Learn the stack and the threat landscape.

  • Days 1-6

    The First Sign

    An overnight SSH anomaly and unusual process activity. Triage it, run Linux CLI forensics, write your first incident ticket.

  • Days 7-14

    The Hook

    A phishing email, four clicks, a C2 beacon and 23 queued alerts. Analyse AI-written phishing headers, trace the beacon, isolate the endpoint.

  • Days 13-19

    The Command Centre

    The domain controller is reached and a maldoc surfaces. Write KQL in Microsoft Sentinel, detect DCSync, reverse the macro.

  • Days 20-26

    The Machine Learns to Lie

    LLM prompt injection, AI phishing, UEBA bypass and ML poisoning, detected against MITRE ATLAS.

  • Days 27-33

    Cloud Nine, Ground Zero

    An AWS admin role assumed, S3 exfiltrated and a Lambda backdoor left behind.

Who Should Attend

🎓

Graduates & Career Switchers

Fresh graduates, career switchers, and IT support, helpdesk or NOC staff moving into a Tier-1 SOC analyst role — provided you are already comfortable with a terminal and basic log triage.

🛡️

Working L1/L2 Analysts

SOC analysts already on the queue who have not yet worked an AI-era or cloud-native incident end to end, and want the 2024–2025 attacker techniques their existing training skipped.

🏢

Corporate & Campus Cohorts

Teams training together ahead of a SOC hire, internship, or internal role transition. The format is built for a cohort of 12–20 learning as a group, not for self-paced study.

How You’ll Be Certified

1

Ground

Sessions 1 to 3 carry only the foundation lessons M3 and M4 formally depend on — Linux CLI, log analysis, KQL, incident reporting, and AD credential forensics. The other 20 foundation lessons in arcs M1 and M2 are left out of the live sessions and worked in the lab course instead.

7 of 27 foundation lessons taught live

2

Investigate

Sessions 2 to 4 deliver AI-Era Threat Investigation in full: AI phishing, prompt injection against Copilot, Slack AI and ServiceNow, deepfake and voice-clone cases, UEBA bypass, and adversarial ML.

Arc M3 · every lesson and micro-project, taught live

3

Hunt in the Cloud

Sessions 4 to 6 run AI-Era Cloud SOC end to end — cloud log sources, IAM privilege escalation, S3 exfiltration, Lambda persistence, cross-cloud lateral movement, and SOAR automation.

Arc M4 · every lesson and micro-project, taught live

4

Leave With a Portfolio

Every lesson and micro-project produces a downloadable incident report. You finish with a body of investigation work a recruiter can open and read — not a quiz score. The only assessment across the six Saturdays is the certification exam on the final immersive day.

Portfolio of incident reports

How this maps to certification domains

The six sessions are not exam prep and the credential you earn is CyBe’s own. These counts come from mapping each session in the schedule above against the awarding bodies’ published exam objectives — including the domains this programme does not cover, which are named rather than omitted.

Microsoft3 of 3

Microsoft Security Operations Analyst (SC-200)

All three functional groups: managing the environment, incident response, and KQL threat hunting — taught on live Sentinel.

EC-Council7 of 8

EC-Council Certified SOC Analyst (312-39)

7 of 8 modules. Malware reverse-engineering is out of scope here; the forensics and cloud-SOC modules are covered in depth.

CompTIA3 of 4

CompTIA Cybersecurity Analyst (CySA+)

3 of 4 domains: security operations, incident response, and reporting. Vulnerability management is not part of this programme.

Certification names and logos are the property of their respective owners and are used here only to identify the credentials this curriculum maps to. CyBe Global is not affiliated with, endorsed by or accredited by Microsoft, EC-Council or CompTIA, and this programme is not an official preparation course for any of their exams. EC-Council logo: Wikimedia Commons, CC BY-SA 4.0.

Faculty for This Course

SD

Satyavathi Divadari

CEO & Founder · CyBe Global / CSA Bangalore

MB

Madhukeshwar Bhat

Academia Advisor · CSA Bangalore Chapter

Course Advisors

Practising security leaders who review this curriculum and keep it current.

See all 13 advisors →

R S Lakshminarayanan

GM & Regional CISO · Wipro Limited

Ravi Subbiah

Managing Partner · TCS Ltd

Vishal Saraswat

Head, Research & Innovation, Cybersecurity · Bosch Software

Sai Lakshmi Sathyanarayana

Partner, Cyber Leader · EY GDS

What Learners Say

This was different learning experience all together. So much fun and so much to learn. The energy was continuously high to know what’s next. Not just regular content but every time something new and different. I recommend this learning methodology to every learner.

PJ

Pravinkumar Jha

Head of Product and Cloud Security

That sounds like such a refreshing change from usual conferences. Learning through music and teamwork really makes complex concepts stick in a fun way.

RP

Rohan Pinto

CTO and Founder, 1Kosmos

Frequently Asked Questions