Attack detection
Run the simulated attack scenario and identify the resulting detections in the sample logs.
Cybersecurity · Security operations
Detect and investigate a simulated attack from endpoint/network/cloud logs.
Capstone in SOC Analyst & Incident Response.
The project brief
A SOC investigation needs to connect detections and response decisions to evidence from endpoint, network and cloud logs.
Shared method: define the requirement, design and build the solution, then test and document the result.
Project brief
Use these scenarios to plan the project review. They describe intended checks, not completed learner results.
Run the simulated attack scenario and identify the resulting detections in the sample logs.
Use endpoint, network or cloud records to construct the sequence of events.
Select response actions for the simulated incident and explain the supporting evidence.
Inside the working solution
Your final submission
Technology workspace
Review the tools and skills used in this project brief.
Centralise security events for investigation and detection
Use Log analysis within guided implementation, testing and portfolio workflows
Use Detection rules within guided implementation, testing and portfolio workflows
Use Incident response within guided implementation, testing and portfolio workflows
Project brief
Review the detection evidence, incident sequence and response decisions.
Questions about this project
Check the recommended level, tools and guidance before selecting a programme.
The associated course is taught at intermediate–advanced level. Review its prerequisites before choosing this capstone. An adviser can help you confirm the appropriate starting point.
The project brief uses SIEM, Log analysis, Detection rules, Incident response. Confirm the selected stack with admissions when choosing a programme.
Ask admissions to confirm the mentor reviews, feedback and final walkthrough included in your selected programme.
Request the exact training scope
Ask about the curriculum, prerequisites, mentor reviews and recommended programme for SOC Detection and Response Challenge.
Receive the project scope, tools, mentor review process and recommended programme for SOC Detection and Response Challenge.
Secure enquiry. Your details are used only for admissions guidance.