CHFI, Computer Forensics
The standard L2 progression: moving from detecting incidents to investigating and proving them.
View courseBangalore runs a large share of India's security operations centres, and SOC analyst is the single highest-volume entry point into the profession. This 40-hour Certified SOC Analyst programme trains you for that seat specifically: reading telemetry, triaging alerts, escalating with evidence and documenting what happened.
The course is deliberately defensive. Where an ethical hacking course teaches you to break in, this one teaches you to notice someone breaking in, at three in the morning, across a queue of four hundred alerts, most of which are noise. That skill is what SOC hiring managers are actually testing for.
Graduates target SOC Analyst (L1/L2), Security Monitoring Analyst, Incident Response Associate and Threat Detection Analyst roles.
Every module pairs instruction with lab work. You practise the technique in the same session you learn it.
| 01. Security operations centre fundamentals How a SOC is structured, what L1, L2 and L3 actually do, and how work flows between them. |
| 02. Log sources and telemetry Where evidence comes from: endpoints, firewalls, proxies, identity providers and cloud audit logs. |
| 03. SIEM architecture and operation Ingestion, normalisation, correlation rules, and why tuning is a permanent job. |
| 04. Alert triage and prioritisation Working a live queue: what to investigate, what to close, and how to justify both. |
| 05. Threat intelligence in daily operations Applying IOCs and TTPs to enrich an alert instead of collecting feeds for their own sake. |
| 06. Incident detection and analysis Reconstructing an attack chain from fragmentary evidence across multiple log sources. |
| 07. Incident response workflow Containment, eradication and recovery, and the handover points between roles. |
| 08. MITRE ATT&CK mapping Describing adversary behaviour in the shared vocabulary your reports will be read in. |
| 09. Documentation, escalation and shift handover Writing notes the next analyst can act on without asking you a question. |
Batch dates vary; the sequence does not. Weekday, weekend and evening formats cover the same blocks.
| Block | Hours | Focus |
|---|---|---|
| Sessions 1-2 | 8 hrs | SOC structure and log sources How a SOC is organised, what L1, L2 and L3 actually do, and where evidence comes from across the estate. |
| Sessions 3-4 | 8 hrs | SIEM architecture and operation Ingestion, normalisation and correlation. Why tuning is permanent work rather than a setup task. |
| Sessions 5-6 | 8 hrs | Alert triage and prioritisation Working a live queue: what to investigate, what to close, and how to defend both decisions to a shift lead. |
| Sessions 7-8 | 8 hrs | Detection, analysis and threat intelligence Reconstructing attack chains from fragmentary evidence, and using intelligence to enrich rather than to collect. |
| Sessions 9-10 | 8 hrs | Incident response, ATT&CK mapping and reporting Containment and escalation workflow, MITRE ATT&CK mapping, documentation and shift handover discipline. |
| Tool | Used for |
|---|---|
| SIEM platform | Log aggregation, correlation and alert generation |
| Endpoint and EDR telemetry | Host-level process and behaviour evidence |
| Firewall, proxy and DNS logs | Network-side evidence and egress analysis |
| Identity provider logs | Authentication anomalies and access abuse |
| MITRE ATT&CK Navigator | Behaviour mapping and coverage assessment |
| Threat intelligence sources | IOC and TTP enrichment |
| Ticketing and case management | Escalation, documentation and handover |
| Exam code | 312-39, EC-Council Certified SOC Analyst |
| Format | Multiple choice, proctored |
| Question count and duration | Confirm current specification at enrolment |
| Certification validity | 3 years, renewable via EC-Council ECE credits |
The standard L2 progression: moving from detecting incidents to investigating and proving them.
View courseUnderstanding the attacker's methodology makes you a materially better detection analyst.
View courseThree things, in order. Build networking and operating system fundamentals so you can tell normal traffic from abnormal. Learn the analyst workflow, SIEM operation, log analysis, alert triage and incident response, which is what this course covers. Then build evidence you can talk about in an interview: lab investigations you have actually worked through. A certification such as CSA helps you pass the CV screen, but the interview is where the lab work earns you the job.
Volume and structure. Security operations centres hire more entry-level staff than any other security function, run defined shift roles with clear progression from L1 to L2 to L3, and Bangalore hosts a large concentration of enterprise and managed SOCs. For a career changer, it is usually the shortest credible path to a first security job.
No. CEH and CSA address different sides of the discipline and neither is a prerequisite for the other. What you do need is solid security and networking fundamentals, which our Foundations or Basics Mastery courses provide.
The programme is built around SIEM operation, log analysis and incident workflow tooling, with labs that mirror an enterprise monitoring environment. We focus on transferable analytical skill rather than one vendor's interface, because platforms differ between employers.
Entry-level SOC analyst salaries in Bangalore vary considerably by employer type, with managed service providers and product companies at different ends of the range. We would rather give you current figures in a counselling conversation than publish a number that ages badly, call us and we will talk you through what we are seeing from hiring partners.
Yes. The 40-hour programme runs in weekend and evening formats at Marathahalli and online, which is how most career changers complete it while employed.
Core cyber security fundamentals spanning endpoints, networks, web security, IAM, SOC and governance.
View courseBeginner-to-job-ready programme with live labs, SOC operations, ethical hacking and compliance coverage.
View courseEthical hacking fundamentals covering reconnaissance, exploitation, reporting, tooling and attacker methodology.
View courseAdvanced offensive security: simulate real attacks to identify and prove exploitable weaknesses.
View courseDigital forensics covering evidence handling, DFIR workflows, incident investigation and compliance reporting.
View courseSpeak to a counsellor about batch dates, fees and whether this course fits your current background. No obligation, no sales pressure.