View all industry projects

Cybersecurity · Security operations

SOC Detection and Response Challenge

Detect and investigate a simulated attack from endpoint/network/cloud logs.

Capstone in SOC Analyst & Incident Response.

Recommended effort24 hoursCourse levelIntermediate–AdvancedSuggested teamIndividual or team of 2-3

The project brief

The business challenge

A SOC investigation needs to connect detections and response decisions to evidence from endpoint, network and cloud logs.

Shared method: define the requirement, design and build the solution, then test and document the result.

Project brief

Test scenarios

Use these scenarios to plan the project review. They describe intended checks, not completed learner results.

01 · Test scenario

Attack detection

Run the simulated attack scenario and identify the resulting detections in the sample logs.

02 · Test scenario

Incident timeline

Use endpoint, network or cloud records to construct the sequence of events.

03 · Test scenario

Response decision

Select response actions for the simulated incident and explain the supporting evidence.

Inside the working solution

What you will build

  • 01Detections for a simulated attack
  • 02Investigation using endpoint, network or cloud logs
  • 03Incident timeline, report and response actions

Your final submission

What you will present

  • Detection rules
  • Timeline
  • Incident report
  • Response actions

Technology workspace

The tools behind the build

Review the tools and skills used in this project brief.

SIEM

Centralise security events for investigation and detection

Log analysis

Use Log analysis within guided implementation, testing and portfolio workflows

Detection rules

Use Detection rules within guided implementation, testing and portfolio workflows

Incident response

Use Incident response within guided implementation, testing and portfolio workflows

Project brief

Acceptance criteria

Review the detection evidence, incident sequence and response decisions.

  • Detection rules identify the simulated attack in the supplied logs.
  • The timeline and incident report cite the investigation evidence.
  • Response actions are documented and linked to the incident findings.

Questions about this project

SOC Detection and Response Challenge FAQs

Check the recommended level, tools and guidance before selecting a programme.

Who is the SOC Detection and Response Challenge project suitable for?+

The associated course is taught at intermediate–advanced level. Review its prerequisites before choosing this capstone. An adviser can help you confirm the appropriate starting point.

Which tools and skills are used?+

The project brief uses SIEM, Log analysis, Detection rules, Incident response. Confirm the selected stack with admissions when choosing a programme.

Is mentor guidance included?+

Ask admissions to confirm the mentor reviews, feedback and final walkthrough included in your selected programme.

Request the exact training scope

Explore this project with admissions

Ask about the curriculum, prerequisites, mentor reviews and recommended programme for SOC Detection and Response Challenge.

  • Project module and tool breakdown
  • Recommended prerequisites and programme
  • Demo class and upcoming batch guidance
Project curriculum request

Explore this project in training

Receive the project scope, tools, mentor review process and recommended programme for SOC Detection and Response Challenge.

Secure enquiry. Your details are used only for admissions guidance.