CyBe AI Summit 2026 — NIMHANS Convention Centre, Bengaluru — 4 Sep 2026Learn more
← AI SOC Analyst weekend cohortSession 1 of 6 · Sat 17 Oct 2026 · Arc 0–1 · chapters 0.2–3

Foundations and the first alert

The cohort opens with the environment every later session builds on: how a SOC actually receives work, what an alert queue looks like under load, and the first signal of the breach that will take the next six Saturdays to unravel.

When
Sat 17 Oct 2026 · 10:30–13:30 IST
Where
Bangalore or virtual
Cohort size
25 in person · 40 including virtual
₹2,700₹4,50040% off release price
Book this session →

Sessions can be booked individually, or take the full six-session cohort.

What you leave able to do

  • Work a live alert queue and defend your triage order
  • Read the first indicators of the Noowapay intrusion
  • Set up the lab environment used across all six sessions

Run of play

  1. 1

    How a SOC receives work

    Queues, severities, and why the loudest alert is rarely the one that matters.

  2. 2

    First contact

    The opening signal of the breach, worked live.

The case

Where this sits in the story

All six Saturdays run on one continuous breach, so every session picks up where the last one left off.

Three weeks before you arrive, a four-minute anomaly hits NoowaPay's network at 02:47 and the grid team calls it a glitch. Nobody yet knows it was Silent Phantom's first touch. Session 1 is your orientation and your first shift: the SSH noise on a bastion host that has Klaus uneasy, because it has the same patient, low-and-slow shape.

Who this session suits

Career switchers and IT professionals moving into security. No prior SOC experience assumed — this is the session that builds the floor everything else stands on.

Scope

What this session covers

  • What a SOC is for, and how detect/analyse/respond actually divide up
  • Analyst tiers, escalation, and why alert fatigue is a staffing problem
  • NIST CSF as the map analysts classify their work against
  • The NoowaPay stack: SIEM, EDR, SOAR and the log sources feeding them
  • Reading /var/log/auth.log and proving whether a brute force succeeded
  • grep, awk, sort and uniq as the analyst's core toolkit
  • Correlating one attacker across syslog, Apache, firewall and JSON logs

Hands-on

The labs you work

7 hands-on labs, 265 minutes of lab time. Each runs in a cloud terminal against real evidence — logs, PCAPs, event data — and is graded on what you find, not on a multiple-choice answer. Lab access continues for 3 months, so the work does not stop when the session ends.

  1. 1SOC Roles & Analyst Tierssoc-orientation20 min
  2. 2What is a SOC?soc-orientation25 min
  3. 3NIST CSF & Security Frameworkssoc-orientation20 min
  4. 4The NoowaPay Tech Stacksoc-orientation20 min
  5. 5Chapter 1: Your First Shiftsoc-foundations55 min
  6. 6Linux CLI for SOC Analystssoc-foundations75 min
  7. 7Log Analysis 101soc-foundations50 min

Tools used

  • Linux CLI
  • grep / awk / sed
  • jq
  • auth.log
  • syslog
  • Apache access logs

MITRE ATT&CK coverage (16)

  • T1003 OS Credential Dumping
  • T1033 System Owner/User Discovery
  • T1036 Masquerading
  • T1046 Network Service Discovery
  • T1048 Exfiltration Over Alternative Protocol
  • T1057 Process Discovery
  • T1078 Valid Accounts
  • T1083 File and Directory Discovery
  • T1110 Brute Force
  • T1110.001 Brute Force: Password Guessing
  • T1119 Automated Collection
  • T1190 Exploit Public-Facing Application
  • T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching
  • T1562 Impair Defenses
  • T1588 Obtain Capabilities
  • T1595 Active Scanning

Schedule

The full cohort

One continuous case across six Saturdays. Sessions build on each other, and each one can also be booked on its own.

  • Sat 17 Oct 2026Foundations and the first alert10:30–13:30 ISTYou are here
  • Sat 24 Oct 2026AI-era phishing and the initial foothold10:30–13:30 ISTDetails →
  • Sat 31 Oct 2026Endpoint investigation and containment10:30–13:30 ISTDetails →
  • Sat 7 Nov 2026Diwali holiday — no sessionNo session
  • Sat 14 Nov 2026Cloud SOC and lateral movement10:30–13:30 ISTDetails →
  • Sat 21 Nov 2026Detection engineering and automation10:30–13:30 ISTDetails →
  • Sat 28 Nov 2026Immersive day and certification exam10:30–17:30 IST · full dayDetails →

Taking the whole cohort?

The six sessions are one continuous case, and the full course page carries the curriculum, the certification detail and the cohort pricing.