Defensive Security, Digital Forensics & Incident Response

CA302: Operational Cyber Defenses

Course authored by:

Perparim Mjeku, Rinor Shehu, Altin Gashi

26 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

20 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Intermediate level

Developing practical skills and deepening understanding of core concepts

Course Materials

Available after purchase

Course Overview

Operational Cyber Defense is not about watching dashboards it is about detecting and responding to threats in real time under pressure. Built around five sections of focused operational practice, the track develops practical Blue Team capability aligned with modern Security Operations Centers (SOC). You will work through core structures including SOC workflows, team roles, and governance models that define real-world operations. The course focuses on network and endpoint monitoring techniques used to identify and investigate suspicious activity. You will engage with detection engineering, threat hunting, and alert triage processes that separate signal from noise. Log management, SIEM systems, and automation are applied to simulate modern security operations environments. Advanced topics such as threat intelligence integration and purple team collaboration reinforce operational awareness. Expect fast-paced scenarios, high standards, and no tolerance for passive learning by the end, you will be able to function effectively inside a SOC and respond to real-world cyber threats.

What You’ll Learn

Develop the skills required to detect, analyze, and respond to cyber threats in real-time environments

  • Understand Blue Team roles and SOC operations

  • Perform continuous monitoring of networks and endpoints

  • Analyze logs and security telemetry for threat detection

  • Conduct alert triage, prioritization, and incident classification

  • Apply detection engineering and threat hunting methodologies

  • Use SIEM, EDR/XDR, and security monitoring tools

  • Implement incident response processes and playbooks

  • Understand threat intelligence workflows (IOC vs IOA)

  • Automate security operations using SOAR and playbooks

  • Improve detection coverage using MITRE ATT&CK mapping

Business Takeaways

Understand how operational cyber defense strengthens organizational resilience and reduces risk

  • Detect and respond to threats before they escalate into major incidents

  • Minimize downtime and operational disruption from cyberattacks

  • Improve security visibility across networks, endpoints, and systems

  • Strengthen incident response readiness and recovery capabilities

  • Support compliance with security frameworks and regulations

  • Reduce financial and reputational impact of breaches

  • Enable proactive defense through threat intelligence and monitoring

  • Enhance coordination between security, IT, and leadership teams

Syllabus: 5 Sections to Transformation

The CA302 program immerses you in a five-section, real-world defensive cybersecurity simulation, where you operate as part of a modern SOC under constant pressure. Each section escalates from foundational monitoring to advanced threat detection, incident response, and automation workflows.

syllabus overview

Justify Training to Your Manager

section 1

FOUNDATIONS: BLUE TEAM & SOC OPERATIONS

The first section introduces the fundamentals of defensive cybersecurity. You will understand the role of the Blue Team, how Security Operations Centers (SOC) function, and how organizations structure their defensive capabilities.

TOPICS COVERED

  • Blue Team roles: analysts, incident responders, threat hunters.
  • Red Team vs Blue Team vs Purple Team collaboration.
  • SOC structure, governance, and operating models.
  • SOC processes: monitoring, escalation, and incident handling.
  • Threat intelligence basics: IOC vs IOA and detection mapping.

LABS

  • SOC Workflow Simulation
  • IOC vs IOA Identification Exercise

section 2

NETWORK SECURITY & MONITORING

This section focuses on visibility across networks. You will learn how defenders monitor traffic, detect anomalies, and secure network infrastructure.

TOPICS COVERED

  • Network security monitoring concepts.
  • Logs and telemetry collection.
  • Network segmentation and access control (VLANs).
  • Firewalls, routers, and IDS/IPS systems.
  • Detecting DNS and HTTP(S) based attacks.

LABS

  • Logs & network architecture for monitoring
  • Network access control and VLANs
  • IDS/IPS with Snort – modified to be added
  • Packet analysis with Wireshark
  • Firewall rule design & testing
  • Network traffic baselining & anomaly detection

section 3

ENDPOINT SECURITY & THREAT DETECTION

Section 3 shifts to endpoint visibility and detection engineering. You will learn how attacks appear on systems and how defenders detect and respond.

TOPICS COVERED

  • EDR/XDR concepts and response actions.
  • Endpoint attack techniques (Windows & Linux).
  • Vulnerability and patch management lifecycle.
  • Identity-based attacks and monitoring.
  • Detection engineering fundamentals and threat hunting workflows.

LABS

  • Monitoring Local System Activity
  • Windows attack simulation & detection
  • Vulnerability scan & patch validation

section 4

EVENT MANAGEMENT & LOG ANALYSIS

This section focuses on the core operational workflow: how events become alerts and how incidents are handled.

TOPICS COVERED

  • Event correlation and alert generation.
  • Alert triage, prioritization, and classification.
  • Incident management lifecycle and playbooks.
  • Log management: collection, retention, and analysis.
  • Windows and Linux log analysis.

LABS

  • YARA rule development
  • Detection engineering lab
  • Setting up Splunk for Linux
  • Setting up ELK for SOC
  • Log correlation investigation
  • Incident timeline reconstruction

section 5

SIEM, AUTOMATION & INCIDENT RESPONSE

The final section focuses on advanced operational tooling and real-world response, bringing everything together into a complete defensive workflow.

TOPICS COVERED

  • SIEM architecture and use cases.
  • SOAR and automation in incident response.
  • Detection-to-response workflows.
  • Incident response lifecycle and forensics basics.
  • Evidence handling, analysis, and reporting.

LABS

  • SIEM and XDR with Wazuh
  • SIEM use case development
  • SOAR playbook automation

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

What does a Blue Team actually do in real cybersecurity operations?

A Blue Team is responsible for defending an organization against cyber threats through continuous monitoring, alert triage, incident response, and threat hunting. Their role is not just reactive, they also proactively improve detection and reduce risk across systems and networks.

You will gain hands-on operational skills including alert triage and incident investigation, log analysis and event correlation, threat hunting using intelligence and hypotheses, using tools like SIEM, EDR, and network monitoring systems, and following structured incident response workflows.

Detection is based on analyzing logs from Windows, Linux, and network sources, alerts from SIEM and EDR tools, and behavioral patterns such as indicators of attack (IOAs) versus indicators of compromise (IOCs).
Once detected, incidents follow a structured process: identify, triage, contain, eradicate, recover, report.

Reactive SOC analysis involves responding to alerts generated by tools, while proactive threat hunting focuses on searching for hidden threats that bypass detection. Threat hunting emphasizes attacker behavior and tactics, techniques, and procedures (TTPs), using intelligence to uncover advanced or stealthy attacks before damage occurs.

Modern SOCs improve efficiency by tuning detection rules and correlation logic, using threat intelligence to prioritize alerts, automating response with SOAR playbooks, and applying behavior-based detection using indicators of attack instead of relying only on indicators of compromise.

0
    Your Cart
    Your cart is empty