Advanced SOC Operations
Detection engineering, purple teaming, and SOC at scale
The follow-up to AYSEC-102. SOC maturity models, detection-as-code pipelines (Sigma → CI → SIEM), purple-teaming workflows, automation with SOAR, false-positive reduction, threat intel integration, hunt scaling. For senior analysts moving into Tier 3 / Detection Engineering / SOC Manager roles.
Lessons
- SOC Maturity & Metrics
- SOAR & Automation
- Detection Engineering Lifecycle (Deep)
- Splunk Deep Dive
- Sentinel + KQL Deep Dive
- EDR Vendor Operations
- Identity Threat Detection & Response (ITDR)
- Deception, Honeypots, and Honeytokens
- OT / ICS SOC
- Cloud-Native Detection (CDR / CNAPP)
- UEBA & Insider Threat Programs
- Capstone: Stand Up a SOC From Scratch