SEC450.1.1 — SOC Overview
Core components of security operations, SOC mission, risk appetite, org structures, and governance.
SEC450.1.2 — Defensible Network Concepts
Understanding defensible networks, network vs host monitoring, data collection, and log centralization.
SEC450.1.3 — Security Events, Alerts, Anomalies & Incidents
Differentiating events, alerts, and incidents, alert triage workflows, and reducing false positives.
SEC450.1.4.1 — Incident Management Systems
Ticketing and case management systems, security playbooks, metrics tracking, and investigation lifecycle.
SEC450.1.4.2 — TheHive Project (THM Room)
Hands-on walkthrough of TheHive Project room on TryHackMe, setting up cases, observables, and Cortex analyzers.
SEC450.1.5.1 — Threat Intelligence Platforms
Fundamentals of Cyber Threat Intelligence (CTI), threat intel platforms, IOC feeds, and platform workflows.
SEC450.1.5.2 — OpenCTI (THM Room)
Practical guide and solution for OpenCTI TryHackMe room, exploring STIX2 structures, entities, and threat actor mapping.
SEC450.1.5.3 — MISP (THM Room)
Complete walkthrough of MISP room on TryHackMe, event creation, attribute correlation, and threat intelligence sharing.
SEC450.1.6 — SIEM & Automation
SIEM capabilities, log aggregation, Kibana searching, rule creation, and SOAR automation integration.








