Get your OSDA certification with SOC-200 | OffSec

Train to become OSDA certified

SOC-200: Security Operations and Defensive Analysis

Starting at $1,749

Level

200
|

277h of content

  • Learn the basics of security operations, including configuring intrusion detection systems, incident response, and building and operating defensive measures for enterprise protection
  • Become a certified OffSec Defense Analyst (OSDA)

Overview

SOC-200 focuses on building foundational skills in defending networks and systems by analyzing logs, detecting cyber threats, and utilizing security tools like ELK and Splunk to respond to incidents in both Windows and Linux environments

SOC-200 (Security Operations and Defensive Analysis) is a defensive-minded course covering the foundations of defending networks and systems against cyber threats. The course will focus on developing techniques for easily parsing and analyzing logs, which can be performed at scale. This more manual approach ensures a better understanding of how logs and artifacts are generated and how they can be queried in both Windows and Linux environments. Along the way, learners will develop an understanding of network security incidents and detection techniques.

SOC-200 equips learners with a wide range of practical skills and defensive techniques, including:

  • Understanding Windows endpoint security, including desktops, laptops, and other user devices, along with the threats and vulnerabilities that affect them
  • Identifying social engineering and spear phishing tactics, two of the most common attack methods used by adversaries
  • Using the Invoke-Obfuscation framework to automate PowerShell obfuscation and create realistic traps for simulated attackersExploring Linux endpoint concepts, including security mechanisms and common vulnerabilities, to understand how attackers target Unix-based systemsLeveraging administrative groups such as Domain Admins, Enterprise Admins, and Full Administrators to understand access control in secure domain environmentsDeploying and working with SIEM tools like ELK and Splunk to monitor logs, detect anomalies, and investigate security incidents

SOC-200 is organized into 19 modules, many with companion videos for learners who prefer a more visual presentation of the information. Each of the modules also includes hands-on activities and labs, which allow the learners to "show their work" and prove they have completed and understand what was covered. Once learners have completed the course materials, there are more than a dozen Challenge Labs to test their ability to bring all of the concepts together and actually defend their infrastructure against attackers. Once they are ready, learners can sit for the OSDA exam, where they will demonstrate their ability to identify, analyze, and respond to potential threats within a live lab environment.

SOC-200 is for anyone looking to take a serious step into the world of information security and learn the skills of detecting cyber attacks. The course material will describe how to detect a variety of attacks and techniques used by malicious entities against enterprises. To be successful in this course, learners should have a solid foundation in TCP/IP networking, a familiarity with Linux and Windows operating systems, and a basic understanding of cybersecurity concepts.

Becoming OSDA certified

  • 24-hour proctored

    All exams are proctored by an OffSec employee in a private VPN

  • Hands-on labs

    Identify, exploit, and report real-world vulnerabilities in live lab systems

  • Simulated corporate events

    The exam network includes a SIEM with endpoint integration

  • 10 exam phases

    Each phase contains a number of attacker actions that must be detected, understood, and documented

OSDA certification

About the OSDA exam

The OffSec Defense Analyst certification validates your expertise in macOS security and demonstrates your ability to detect, analyze, and assess a potential security incident through live exercises

Start learning with OffSec

$2,749/year*

Best value

Learn One

Includes one year of access to one 200 or 300-level course, the associated labs, and two exam attempts

$1,749/once

Most popular

Course + Cert Bundle

Includes 90 days of access to one 200 or 300-level course, the associated labs, and a single exam attempt

Train your team with OffSec

$6,099/year*

All access

Learn Unlimited

Unlimited OffSec Learning Library access plus unlimited exam attempts for one year

Get a quote

Large teams

Learn Enterprise

Unlimited OffSec Learning Library access with flexible terms and volume discounts available

Validate your expertise.
Amplify your impact.

  • Mindset & work ethic

    Instill a relentless problem-solving mindset that employers value highly in security professionals

  • Globally recognized certification

    OffSec certs build elite, hands-on skills trusted by the world's top companies

  • Organization value & trust

    Trusted to train skilled, consistent, and reliable security teams

  • Certified candidates win

    91% of respondents prefer to hire candidates with certifications (Fortinet, 2024 Cybersecurity Skills Gap Report)

View of the PEN-200 syllabus in the OffSec portal

Realistic lab environments

Built to sharpen skills through practical, immersive learning

Request a free trial
View of the PEN-200 syllabus in the OffSec portal
  • On-demand lab access

    Train anytime in up-to-date, practical, cutting-edge labs

  • Structured learning modules

    Progress through clear, goal-driven topics

  • Challenge-based learning

    Build skills through real-world, hands-on challenges

  • AI-powered learning assisstant

    Get instant, guided help with complex topics

Success stories from the field

It's been quite a journey and hard work, in truth, but I have finally made it. The intensive training and challenging examination of this course endowed me with advanced skills to detect, analyze, and mitigate threats in a manner that enhances our ability to protect and defend organizational assets against cyber threats.
Yusuf Efil SOC Analyst
I gained expertise in using SIEM tools for monitoring and analyzing security events. My training covered threat hunting, advanced log analysis, and defensive techniques for system protection. Additionally, I learned about hacker tactics, enabling me to anticipate and counter threats.
Malek Ezzar Cyber Security Consultant

SOC-200 FAQ