Train to become OSDA certified
SOC-200: Security Operations and Defensive Analysis
Starting at $1,749
Level
200277h of content
- Learn the basics of security operations, including configuring intrusion detection systems, incident response, and building and operating defensive measures for enterprise protection
- Become a certified OffSec Defense Analyst (OSDA)
Overview
SOC-200 focuses on building foundational skills in defending networks and systems by analyzing logs, detecting cyber threats, and utilizing security tools like ELK and Splunk to respond to incidents in both Windows and Linux environments
SOC-200 (Security Operations and Defensive Analysis) is a defensive-minded course covering the foundations of defending networks and systems against cyber threats. The course will focus on developing techniques for easily parsing and analyzing logs, which can be performed at scale. This more manual approach ensures a better understanding of how logs and artifacts are generated and how they can be queried in both Windows and Linux environments. Along the way, learners will develop an understanding of network security incidents and detection techniques.
SOC-200 equips learners with a wide range of practical skills and defensive techniques, including:
- Understanding Windows endpoint security, including desktops, laptops, and other user devices, along with the threats and vulnerabilities that affect them
- Identifying social engineering and spear phishing tactics, two of the most common attack methods used by adversaries
- Using the Invoke-Obfuscation framework to automate PowerShell obfuscation and create realistic traps for simulated attackersExploring Linux endpoint concepts, including security mechanisms and common vulnerabilities, to understand how attackers target Unix-based systemsLeveraging administrative groups such as Domain Admins, Enterprise Admins, and Full Administrators to understand access control in secure domain environmentsDeploying and working with SIEM tools like ELK and Splunk to monitor logs, detect anomalies, and investigate security incidents
SOC-200 is organized into 19 modules, many with companion videos for learners who prefer a more visual presentation of the information. Each of the modules also includes hands-on activities and labs, which allow the learners to "show their work" and prove they have completed and understand what was covered. Once learners have completed the course materials, there are more than a dozen Challenge Labs to test their ability to bring all of the concepts together and actually defend their infrastructure against attackers. Once they are ready, learners can sit for the OSDA exam, where they will demonstrate their ability to identify, analyze, and respond to potential threats within a live lab environment.
SOC-200 is for anyone looking to take a serious step into the world of information security and learn the skills of detecting cyber attacks. The course material will describe how to detect a variety of attacks and techniques used by malicious entities against enterprises. To be successful in this course, learners should have a solid foundation in TCP/IP networking, a familiarity with Linux and Windows operating systems, and a basic understanding of cybersecurity concepts.
Becoming OSDA certified
-
24-hour proctored
All exams are proctored by an OffSec employee in a private VPN
-
Hands-on labs
Identify, exploit, and report real-world vulnerabilities in live lab systems
-
Simulated corporate events
The exam network includes a SIEM with endpoint integration
-
10 exam phases
Each phase contains a number of attacker actions that must be detected, understood, and documented
OSDA certification
About the OSDA exam
The OffSec Defense Analyst certification validates your expertise in macOS security and demonstrates your ability to detect, analyze, and assess a potential security incident through live exercises
Start learning with OffSec
$2,749/year*
Best value
Learn One
Includes one year of access to one 200 or 300-level course, the associated labs, and two exam attempts
$1,749/once
Most popular
Course + Cert Bundle
Includes 90 days of access to one 200 or 300-level course, the associated labs, and a single exam attempt
Train your team with OffSec
$6,099/year*
All access
Learn Unlimited
Unlimited OffSec Learning Library access plus unlimited exam attempts for one year
Get a quote
Large teams
Learn Enterprise
Unlimited OffSec Learning Library access with flexible terms and volume discounts available
Validate your expertise.
Amplify your impact.
-
Mindset & work ethic
Instill a relentless problem-solving mindset that employers value highly in security professionals
-
Globally recognized certification
OffSec certs build elite, hands-on skills trusted by the world's top companies
-
Organization value & trust
Trusted to train skilled, consistent, and reliable security teams
-
Certified candidates win
91% of respondents prefer to hire candidates with certifications (Fortinet, 2024 Cybersecurity Skills Gap Report)

Realistic lab environments
Built to sharpen skills through practical, immersive learning
Request a free trial
-
On-demand lab access
Train anytime in up-to-date, practical, cutting-edge labs
-
Structured learning modules
Progress through clear, goal-driven topics
-
Challenge-based learning
Build skills through real-world, hands-on challenges
-
AI-powered learning assisstant
Get instant, guided help with complex topics
Success stories from the field
It's been quite a journey and hard work, in truth, but I have finally made it. The intensive training and challenging examination of this course endowed me with advanced skills to detect, analyze, and mitigate threats in a manner that enhances our ability to protect and defend organizational assets against cyber threats.
I gained expertise in using SIEM tools for monitoring and analyzing security events. My training covered threat hunting, advanced log analysis, and defensive techniques for system protection. Additionally, I learned about hacker tactics, enabling me to anticipate and counter threats.