Defensive Security, Digital Forensics & Incident Response

CA302: Operational Cyber Defenses

Course authored by:

Perparim Mjeku, Rinor Shehu, Altin Gashi

26 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

20 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Intermediate level

Developing practical skills and deepening understanding of core concepts

Course Materials

Available after purchase

Course Overview

Attackers operate in real time — and defenders who rely on dashboards alone will always be a step behind. This course builds practical Blue Team capability aligned with modern SOC operations across five focused sections. You work through SOC workflows, detection engineering, threat hunting, and alert triage, applying log management, SIEM, and automation to simulate real security operations environments. Advanced topics include threat intelligence integration and purple team collaboration. By the end, you can function effectively inside a SOC and respond to real-world cyber threats under pressure.

What You’ll Learn

* Understand Blue Team roles, SOC workflows, and governance structures
* Perform continuous monitoring of networks and endpoints for suspicious activity
* Conduct alert triage, detection engineering, and threat hunting
* Use SIEM, EDR/XDR, and SOAR platforms in operational scenarios
* Map detection coverage and improve visibility using MITRE ATT&CK

Business Takeaways

* Detect and respond to threats before they escalate into major incidents
* Improve security visibility across networks, endpoints, and systems
* Strengthen incident response readiness and recovery capabilities
* Reduce financial and reputational impact through proactive defense

Syllabus: 5 Sections to Transformation

The CA302 program immerses you in a five-section, real-world defensive cybersecurity simulation, where you operate as part of a modern SOC under constant pressure. Each section escalates from foundational monitoring to advanced threat detection, incident response, and automation workflows.

syllabus overview

Justify Training to Your Manager

section 1

FOUNDATIONS: BLUE TEAM & SOC OPERATIONS

The first section introduces the fundamentals of defensive cybersecurity. You will understand the role of the Blue Team, how Security Operations Centers (SOC) function, and how organizations structure their defensive capabilities.

TOPICS COVERED

  • Blue Team roles: analysts, incident responders, threat hunters.
  • Red Team vs Blue Team vs Purple Team collaboration.
  • SOC structure, governance, and operating models.
  • SOC processes: monitoring, escalation, and incident handling.
  • Threat intelligence basics: IOC vs IOA and detection mapping.

LABS

  • SOC Workflow Simulation
  • IOC vs IOA Identification Exercise

section 2

NETWORK SECURITY & MONITORING

This section focuses on visibility across networks. You will learn how defenders monitor traffic, detect anomalies, and secure network infrastructure.

TOPICS COVERED

  • Network security monitoring concepts.
  • Logs and telemetry collection.
  • Network segmentation and access control (VLANs).
  • Firewalls, routers, and IDS/IPS systems.
  • Detecting DNS and HTTP(S) based attacks.

LABS

  • Logs & network architecture for monitoring
  • Network access control and VLANs
  • IDS/IPS with Snort – modified to be added
  • Packet analysis with Wireshark
  • Firewall rule design & testing
  • Network traffic baselining & anomaly detection

section 3

ENDPOINT SECURITY & THREAT DETECTION

Section 3 shifts to endpoint visibility and detection engineering. You will learn how attacks appear on systems and how defenders detect and respond.

TOPICS COVERED

  • EDR/XDR concepts and response actions.
  • Endpoint attack techniques (Windows & Linux).
  • Vulnerability and patch management lifecycle.
  • Identity-based attacks and monitoring.
  • Detection engineering fundamentals and threat hunting workflows.

LABS

  • Monitoring Local System Activity
  • Windows attack simulation & detection
  • Vulnerability scan & patch validation

section 4

EVENT MANAGEMENT & LOG ANALYSIS

This section focuses on the core operational workflow: how events become alerts and how incidents are handled.

TOPICS COVERED

  • Event correlation and alert generation.
  • Alert triage, prioritization, and classification.
  • Incident management lifecycle and playbooks.
  • Log management: collection, retention, and analysis.
  • Windows and Linux log analysis.

LABS

  • YARA rule development
  • Detection engineering lab
  • Setting up Splunk for Linux
  • Setting up ELK for SOC
  • Log correlation investigation
  • Incident timeline reconstruction

section 5

SIEM, AUTOMATION & INCIDENT RESPONSE

The final section focuses on advanced operational tooling and real-world response, bringing everything together into a complete defensive workflow.

TOPICS COVERED

  • SIEM architecture and use cases.
  • SOAR and automation in incident response.
  • Detection-to-response workflows.
  • Incident response lifecycle and forensics basics.
  • Evidence handling, analysis, and reporting.

LABS

  • SIEM and XDR with Wazuh
  • SIEM use case development
  • SOAR playbook automation

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

What does a Blue Team actually do in real cybersecurity operations?

A Blue Team is responsible for defending an organization against cyber threats through continuous monitoring, alert triage, incident response, and threat hunting. Their role is not just reactive, they also proactively improve detection and reduce risk across systems and networks.

You will gain hands-on operational skills including alert triage and incident investigation, log analysis and event correlation, threat hunting using intelligence and hypotheses, using tools like SIEM, EDR, and network monitoring systems, and following structured incident response workflows.

Detection is based on analyzing logs from Windows, Linux, and network sources, alerts from SIEM and EDR tools, and behavioral patterns such as indicators of attack (IOAs) versus indicators of compromise (IOCs).
Once detected, incidents follow a structured process: identify, triage, contain, eradicate, recover, report.

Reactive SOC analysis involves responding to alerts generated by tools, while proactive threat hunting focuses on searching for hidden threats that bypass detection. Threat hunting emphasizes attacker behavior and tactics, techniques, and procedures (TTPs), using intelligence to uncover advanced or stealthy attacks before damage occurs.

Modern SOCs improve efficiency by tuning detection rules and correlation logic, using threat intelligence to prioritize alerts, automating response with SOAR playbooks, and applying behavior-based detection using indicators of attack instead of relying only on indicators of compromise.

0
    Your Cart
    Your cart is empty