← All courses
Professional Skills Program
AI-Integrated Curriculum
ICT-SOC-101
Cybersecurity Operations & Threat Monitoring
Detect, Triage, and Report Cyber Threats Like a SOC Analyst
About this course
This program trains learners to monitor networks and systems for security events, analyze logs and alerts using industry SIEM tools, and triage, escalate, and report incidents the way a real Security Operations Center (SOC) does. The course culminates in a simulated live-alert SOC exercise. No prior cybersecurity experience required.
Prerequisites
Basic computer literacy and comfort navigating Windows. No networking or security background needed — fundamentals are covered from session one.
Methodology
Hands-on labs with real SIEM tools, log analysis exercises, guided alert investigations, and a capstone SOC simulation with live alerts.
The curriculum
What you'll learn
- CIA triad & security terminology
- Threat actors, attack vectors & malware
- Cyber Kill Chain & MITRE ATT&CK
- PH Cybercrime Law (RA 10175) & Data Privacy Act
- TCP/IP, ports & protocols
- Windows & Linux essentials for security
- Firewalls, IDS/IPS & endpoint protection
- Traffic inspection with Wireshark
- SOC roles, tiers & analyst workflow
- SIEM concepts & log sources
- Hands-on SIEM lab (Wazuh / Splunk Free)
- Detection use cases & dashboards
- Windows events, syslog & web logs
- Indicators of Compromise (IOCs)
- Phishing & malware alert investigation
- Threat intel feeds & AI-assisted triage
- Alert prioritization & severity levels
- Incident response lifecycle (NIST)
- Escalation procedures & ticketing
- Shift handover & incident reports
- Live-alert SOC simulation: monitor → detect → triage → report
- Practical skills assessment: monitoring, triage & reporting
- SOC Analyst Tier 1 career pathing & certifications roadmap
Outcomes
You'll walk away able to…
- Monitor networks and systems for security events using SIEM tools
- Analyze logs and alerts to spot indicators of compromise
- Triage, escalate, and report incidents following SOC workflow
- Complete a simulated live-alert SOC exercise end-to-end