SIEM (SOC Analyst)
I. SIEM & SOC Fundamentals
1. What is SIEM
2. Role of SIEM in SOC
3. SOC Team Structure
4. Logs, Events & Alerts
5. SIEM Architecture
6. Log Sources & Data Types
7. Use Cases & Correlation
8. SIEM Career Paths
II. Log Management & Detection
9. Log Collection & Normalization
10. Parsing & Field Extraction
11. Event Correlation
12. Detection Logic & Rules
13. Threshold vs Behavioral Detection
14. Alert Tuning
15. MITRE ATT&CK Framework
16. MITRE Mapping
17. Dashboards & Visualization
18. Detection Best Practices
III. Incident Response & SOC Ops
19. Alert Investigation
20. Incident Classification
21. False vs True Positives
22. Threat Intelligence
23. IOC Management
24. Case Management
25. Incident Response Lifecycle
26. Containment & Mitigation
27. Root Cause Analysis
28. Reporting & Documentation
29. SOC Metrics & KPIs
30. Shift Handover & Escalation
IV. SIEM Tools & Practice