Security Operations Center (SOC) Analyst L1 & L2

New
AI INTEGRATED COURSE

Security Operations Center (SOC) Analyst L1 & L2

Security Operations, Detection, Incident Response & Threat Hunting

Mode: Physical & Online Live Classes (Day/Night)
Successful student from Broadway Infosys Mr. ⁨Bikram Singh
Successful student from Broadway Infosys Mr. ⁨Bishnu Khojwar
Successful student from Broadway Infosys Mr. Kaveer Chaudhary
Successful student from Broadway Infosys Mr. Alish Bam

Thousands of students have started their careers after getting certified by Broadway Infosys

Updated On: 16/08/2026

Created On: 16/08/2026

Course Overview

The L1 and L2 SOC Analyst Training at Broadway Infosys is a hands-on program that trains aspiring cybersecurity professionals for real-life roles in a Security Operations Center.

The course blends SOC fundamentals, networking, Windows & Linux security monitoring, SIEM operations, incident response, threat intelligence, MITRE ATT&CK, and threat hunting into one structured learning path across 16 modules. It starts with the basics like OSI/TCP-IP, the CIA triad, and common attacks, then moves into live-lab practice. In that part, you use industry-standard tools like Wireshark, Wazuh SIEM, Sysmon, and you do the MITRE ATT&CK mapping too.

You’ll work through the whole incident lifecycle, like Alert  →  Triage  →  Investigation →  Containment → Recovery, and you’ll correlate the logs across the firewall, IDS/IPS, EDR, and cloud sources. The course blends the core SOC ideas with real practice sessions, so at the end you'll be able to triage alerts, analyze log trails, and respond to real incidents, not just describe them.

Why SOC Analyst L1 & L2 Training?

Build real SOC-ready skills: Go beyond theory with hands-on labs in packet analysis, log investigation, and alert triage used daily by working analysts.
Master the SOC analyst toolkit: Get practical experience with Wireshark, Wazuh SIEM, Sysmon, Windows Event Logs, and MITRE ATT&CK, the same tools used in enterprise SOCs.
Understand attacks from both sides: Learn how threats like phishing, ransomware, sideways movement, and data leakage actually work, so you can detect and stop them before they get worse.
Handle the entire lifecycle of an incident: From alert triaging and investigation to containment, eradication, and recovery, aligned with your actual SOC workflows and SLAs.
Learn From Certified Trainers: We offer industry-vetted, certified trainers with practical lab experience to teach each concept, complemented by 100% career placement assistance from our placement teams for career readiness.
L1 to L2 Career Readiness: The program is designed with career readiness in mind to help you grow from junior (L1) responsibilities to advanced ones such as threat hunting and CTI.

Success Stories From our Graduates

Hear from graduates who have completed our courses.

Successful student from Broadway Infosys Mr. ⁨Bikram Singh
Mr. ⁨Bikram Singh
Course: Graphics Design

College/Faculty: Shree Mahendra Adarsh Higher Secondary School / Management

Working At: Creative Production Pvt Ltd

Position: Graphic Designer

Successful student from Broadway Infosys Mr. ⁨Bishnu Khojwar
Mr. ⁨Bishnu Khojwar
Course: React js Training

College/Faculty: National College of Engineering / B.E. Computer

Working At: Cotiviti Nepal Pvt. Ltd.

Position: Software Engineer

Successful student from Broadway Infosys Mr. Kaveer Chaudhary
Mr. Kaveer Chaudhary
Course: CCNA Training

College/Faculty: University of Kurukshetra, India / B.Tech Computer Science & Engineering

Working At: Web Surfer Nepal Communication

Position: Network Administrator

Successful student from Broadway Infosys Mr. Alish Bam
Mr. Alish Bam
Course: CCNA Training

College/Faculty: Amrit Science Campus / BCSIT

Working At: Tech Bucket Pvt. Ltd.

Position: Network Engineer

Our graduates are hired by 470+ companies in Nepal

Time for you to be the next hire. With our advanced and industry relevant courses, you are on the right stage to start your dream career.
Our graduates are hired by

Our syllabus outlines are only the headlines of the major modules. To ensure a complete understanding of the course, we offer free counseling. Also, if you have specific modules in mind, you can customize the course. Send your inquiry today!

  • What is a SOC?
  • SOC objectives
  • SOC functions
  • SOC organizational structure
  • L1, L2, L3 responsibilities
  • SOC Manager
  • Incident Response team
  • Threat Intelligence team
  • Detection Engineering
  • Threat Hunting
  • DFIR
  • Vulnerability Management
  • Security Engineering

  • Alert → Triage → Investigation → Escalation → Containment → Eradication → Recovery → Closure
  • Incident lifecycle
  • Case management
  • Evidence handling
  • Shift handover
  • Escalation procedures
  • Incident severity
  • SLA management

  • MTTD
  • MTTA
  • MTTR
  • False-positive rate
  • Alert volume
  • Alert-to-incident ratio
  • Escalation rate
  • Detection coverage
  • Analyst workload

  • OSI model, TCP/IP model, Ethernet, MAC addresses, IPv4, IPv6, CIDR, Subnetting, ARP, ICMP, TCP, UDP

Important protocols

  • HTTP/HTTPS, DNS, DHCP, SSH, FTP/SFTP, SMTP, IMAP, LDAP, Kerberos, SMB, RDP, SNMP, NTP, TLS

Practical labs

  • Wireshark packet analysis
  • TCP handshake analysis
  • DNS investigation and DNS query/response analysis with Wireshark
  • HTTP investigation
  • SSH traffic analysis
  • TCPdumps
  • Suspicious outbound connection investigation

  • CIA triad
  • Authentication
  • Authorization
  • Accounting AAA
  • Least privilege
  • Defense in depth
  • Zero Trust
  • Attack surface
  • Vulnerabilities
  • Exploits
  • Threats
  • Risk
  • Indicators of Compromise
  • Indicators of Attack

Windows architecture

  • Windows processes, Services, Registry, Users/groups, Security principals, ACLs, UAC, Scheduled Tasks, PowerShell, WMI, Windows Defender

Windows Event Logs

  • Security
  • System
  • Application
  • PowerShell
  • Sysmon
  • Windows Defender
  • Task Scheduler

Linux fundamentals

  • Processes
  • Services
  • systemd
  • Users
  • Groups
  • Permissions
  • Cron
  • SSH
  • /proc
  • /var/log

  • What is SIEM?
  • Log collection
  • Log parsing
  • Normalization
  • Enrichment
  • Correlation
  • Detection
  • Alerting
  • Incident management

Log sources

  • Windows
  • Linux
  • Firewall
  • IDS/IPS
  • EDR
  • Antivirus
  • VPN
  • Proxy
  • DNS
  • DHCP
  • WAF
  • Email
  • Cloud
  • Database
  • Application
  • Identity provider

  • Wazuh SIEM

Earn a High Value Industry Certificate

Add this credential to your LinkedIn profile, resume, or CV to stand out to recruiters.

Already earned a certificate? Verify it here
Quick Inquiry

Choose class schedule(s)