Skip to main content
CYB-0326ExpertCurrent Intake
XSOC

XSOC: Xcademia SOC Analyst Practitioner

6-Day Instructor-Led Programme

The XSOC Certification Programme is the practitioner standard for SOC analysts who detect, investigate, and proactively hunt advanced threats across enterprise environments using SIEM, EDR, and cyber threat intelligence. Assessed on Day 6 through a supervised live threat hunt producing a professional intelligence report. No MCQs. No exam pressure. No question bank.

Duration

6 Days

Price

$7,497

XSOC: Xcademia SOC Analyst Practitioner
Duration
6 Days
Complete in 6 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Modern security operations demand more than alert triage and runbook execution. Threat actors blend into normal traffic, adapt their techniques constantly, and evade signature-based detection. The SOC analyst who follows only a playbook is perpetually behind. XSOC is built for professionals who want to operate at the front edge of detection, hunting proactively, engineering better alerts, and producing intelligence that informs strategic decisions.

Across six instructor-led days, participants build capability across the complete SOC lifecycle: platform operations across Splunk, Microsoft Sentinel, and Elastic, detection engineering with Sigma and YARA, alert triage and investigation workflows, endpoint and cloud telemetry analysis, threat hunting methodology, and cyber threat intelligence integration. Every session uses real adversary behaviour drawn from current threat actor profiles and MITRE ATT&CK v14.

On Day 6, participants lead a live supervised hunt exercise against a simulated enterprise environment seeded with real threat actor behaviour. The senior practitioner observes methodology and assesses the intelligence report submitted. Certificate and Practitioner Assessment Report issued together. Aligned with MITRE ATT&CK v14, NCSC CAF Objective C, NIST CSF 2.0 Detect, UK DDaT Cyber Security job family, GovAssure, SOC-CMM, NIS2, and DORA.

Hands-On Learning

Live SIEM exercises across Splunk, Sentinel, and Elastic, alert triage simulations, EDR telemetry analysis, Sigma and YARA rule authoring, threat hunting drills, and a full-day supervised hunt engagement on Day 6.

Mentor-Led Sessions

Mentor-led sessions exploring real adversary TTPs from current threat actor profiles, detection engineering against ATT&CK v14 techniques, and professional intelligence report structure aligned to regulatory reporting obligations.

Career-Ready Skills

Operate as a practitioner-level SOC analyst capable of detection engineering, proactive threat hunting, and producing professional intelligence reports that inform board-level security decisions.

Learning Outcomes

Design and implement detection rules aligned to MITRE ATT&CK v14 using Sigma, YARA, and native SIEM query languages across Splunk, Sentinel, and Elastic

Analyse endpoint, network, and cloud telemetry to identify indicators of compromise and adversary behaviour patterns from current threat actor profiles

Lead hypothesis-driven threat hunting operations from scoping through evidence collection to documented intelligence findings

Manage investigation workflows across L1 to L3 SOC tiers with professional documentation and escalation standards

Integrate cyber threat intelligence from MISP, OpenCTI, and commercial feeds into detection engineering and SOC operations

Produce professional intelligence reports and executive briefings aligned to NIS2, DORA, and NCSC CAF regulatory requirements

Prerequisites

1

Minimum 12 months in a SOC, security operations, or IT infrastructure role with hands-on security exposure

2

Working knowledge of at least one SIEM platform: Splunk, Microsoft Sentinel, or Elastic

3

Basic understanding of TCP/IP networking, Windows and Linux operating systems

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • Tiered SOC models: L1, L2, L3, insource vs MSSP vs hybrid delivery
  • SOC-CMM maturity framework levels 1 to 5 and how to assess current state
  • Shift handover procedures, SLA and SLO management, escalation matrices
  • MTTD and MTTR metrics: calculation, benchmarking, and improvement targets
  • SOC toolstack architecture overview: SIEM, SOAR, EDR, TIP, and ticketing integration
Stage 5Final Capstone

XSOC: Xcademia SOC Analyst Practitioner — Capstone Project

On Day 6, participants receive access to a simulated enterprise SIEM environment containing telemetry from a completed multi-stage attack. They independently identify the attack, map it to MITRE ATT&CK v14, determine the scope of compromise, and produce a structured intelligence report. The senior practitioner observes methodology in real time and assesses both the hunt process and the quality of the intelligence report. The XSOC certificate and Practitioner Assessment Report are issued together on passing standard.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • MITRE ATT&CK v14

    Global

    Primary detection and hunting framework: all techniques mapped throughout including ATT&CK for Cloud and Containers

  • NCSC CAF

    Global

    Objective C, Detect cyber security events: C1 Security Monitoring and C2 Proactive Threat Hunting directly covered

  • NIST CSF 2.0

    Global

    Detect function: continuous monitoring, anomaly and event detection, and detection processes covered throughout

  • UK DDaT Framework

    Global

    Civil Service Digital, Data and Technology Cyber Security job family competency alignment throughout

  • GovAssure

    Global

    UK government cyber resilience programme: detection capability and threat hunting requirements addressed

  • SOC-CMM

    Global

    Security Operations Centre Capability Maturity Model: XSOC maps to Level 3 and Level 4 capabilities

  • NIS2 Article 6 and 23

    Global

    Significant incident detection obligations and mandatory 24-hour reporting requirements covered in Day 5

  • DORA Article 10

    Global

    ICT-related incident detection requirements for EU financial sector entities covered in reporting module

Skills You'll Gain

Master these in-demand skills through hands-on practice

SIEM platform operationsSigma rule authoringYARA developmentMITRE ATT&CK v14 detection mappingThreat hunting methodologyEDR telemetry analysisAlert triage and escalationCloud log analysis. Cyber threat intelligence integrationDetection-as-codeSOC metrics and KPIsIntelligence report writing

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

SOC Analyst L2/L3Detection EngineerThreat HunterSecurity Operations LeadCyber Threat AnalystMSSP Analyst
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

6 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$7,497+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised XSOC: Xcademia SOC Analyst Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of XSOC: Xcademia SOC Analyst Practitioner, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

Both CSA and CySA+ are multiple choice exams. XSOC is six instructor-led days ending in a supervised live threat hunt and intelligence report on Day 6. Participants demonstrate actual detection and hunting capability across three SIEM platforms rather than answering test questions. The Practitioner Assessment Report documents what was demonstrated and who verified it.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options