GESTAAC INC. logo GESTAAC INC.
← All courses
Professional Skills Program AI-Integrated Curriculum ICT-SOC-101

Cybersecurity Operations & Threat Monitoring

Detect, Triage, and Report Cyber Threats Like a SOC Analyst

About this course

This program trains learners to monitor networks and systems for security events, analyze logs and alerts using industry SIEM tools, and triage, escalate, and report incidents the way a real Security Operations Center (SOC) does. The course culminates in a simulated live-alert SOC exercise. No prior cybersecurity experience required.

Prerequisites

Basic computer literacy and comfort navigating Windows. No networking or security background needed — fundamentals are covered from session one.

Methodology

Hands-on labs with real SIEM tools, log analysis exercises, guided alert investigations, and a capstone SOC simulation with live alerts.

The curriculum

What you'll learn

6 modules · 36 hrs
  • CIA triad & security terminology
  • Threat actors, attack vectors & malware
  • Cyber Kill Chain & MITRE ATT&CK
  • PH Cybercrime Law (RA 10175) & Data Privacy Act
  • TCP/IP, ports & protocols
  • Windows & Linux essentials for security
  • Firewalls, IDS/IPS & endpoint protection
  • Traffic inspection with Wireshark
  • SOC roles, tiers & analyst workflow
  • SIEM concepts & log sources
  • Hands-on SIEM lab (Wazuh / Splunk Free)
  • Detection use cases & dashboards
  • Windows events, syslog & web logs
  • Indicators of Compromise (IOCs)
  • Phishing & malware alert investigation
  • Threat intel feeds & AI-assisted triage
  • Alert prioritization & severity levels
  • Incident response lifecycle (NIST)
  • Escalation procedures & ticketing
  • Shift handover & incident reports
  • Live-alert SOC simulation: monitor → detect → triage → report
  • Practical skills assessment: monitoring, triage & reporting
  • SOC Analyst Tier 1 career pathing & certifications roadmap
Outcomes

You'll walk away able to…

  • Monitor networks and systems for security events using SIEM tools
  • Analyze logs and alerts to spot indicators of compromise
  • Triage, escalate, and report incidents following SOC workflow
  • Complete a simulated live-alert SOC exercise end-to-end