Discover Our New Course: Video Editing with DaVinci Resolve Learn More

Security Operations Center (SOC) Analyst L1 & L2

AI INTEGRATED COURSE
New

Security Operations Center (SOC) Analyst L1 & L2

Security Operations, Detection, Incident Response & Threat Hunting

Mode: Physical & Online Live Classes (Day/Night)
Successful student from Broadway Infosys Mr. Dev Pradhan
Successful student from Broadway Infosys Mr. Anish Mishra
Successful student from Broadway Infosys Mr. Ganesh Chaudhary
Successful student from Broadway Infosys Mr. Rashish Regmi

Thousands of students have started their careers after getting certified by Broadway Infosys

Updated On: 16/08/2026

Created On: 16/08/2026

Course Overview

The L1 and L2 SOC Analyst Training at Broadway Infosys is a hands-on program that trains aspiring cybersecurity professionals for real-life roles in a Security Operations Center.

The course blends SOC fundamentals, networking, Windows & Linux security monitoring, SIEM operations, incident response, threat intelligence, MITRE ATT&CK, and threat hunting into one structured learning path across 16 modules. It starts with the basics like OSI/TCP-IP, the CIA triad, and common attacks, then moves into live-lab practice. In that part, you use industry-standard tools like Wireshark, Wazuh SIEM, Sysmon, and you do the MITRE ATT&CK mapping too.

You’ll work through the whole incident lifecycle, like Alert  →  Triage  →  Investigation →  Containment → Recovery, and you’ll correlate the logs across the firewall, IDS/IPS, EDR, and cloud sources. The course blends the core SOC ideas with real practice sessions, so at the end you'll be able to triage alerts, analyze log trails, and respond to real incidents, not just describe them.

Tools Covered

Some of the major industry-relevant tools you'll work with in this course include:

  • SIEM Tools
  • Wazuh
  • Sysmon
  • Suricata
  • Wireshark
  • tcpdump
  • VirusTotal
  • AbuseIPDB
  • URLhaus
  • SOCRadar

Students who got hired learning with us

Hear from graduates who have completed our courses.

Successful student from Broadway Infosys Mr. Dev Pradhan
Mr. Dev Pradhan
Course: Flutter Framework Training

College/Faculty: Apex College / Bachelors in Computer Information System (BCIS)

Working At: IME Life Insurance Ltd.

Position: Flutter Intern

Successful student from Broadway Infosys Mr. Anish Mishra
Mr. Anish Mishra
Course: Flutter Framework Training

College/Faculty: Mahendra Morang Adarsha Multiple Campus (MMAMC) / BCA

Working At: Curiotech Pvt. Ltd

Position: Flutter Intern

Successful student from Broadway Infosys Mr. Ganesh Chaudhary
Mr. Ganesh Chaudhary
Course: Flutter Framework Training

College/Faculty: ISMT College / Bsc.IT

Working At: Trilink I.T Solution

Position: Flutter Intern

Successful student from Broadway Infosys Mr. Rashish Regmi
Mr. Rashish Regmi
Course: UI/UX Design Training

College/Faculty: Lumbini City College / BCA

Working At: COL Thinkspace

Position: UI/UX Design Intern

Our graduates are hired by 470+ companies in Nepal

Time for you to be the next hire. With our advanced and industry relevant courses, you are on the right stage to start your dream career.
Our graduates are hired by
Earn a High Value Industry Certificate

Add this credential to your LinkedIn profile, resume, or CV to stand out to recruiters.

Already earned a certificate? Verify it here

Frequently Asked Questions

Anyone interested in cybersecurity and security operations can join the training. Basic knowledge of networking, operating systems, and cybersecurity concepts can be helpful.

Yes. Beginners with an interest in cybersecurity can join the training and gradually build the technical knowledge required to work in a Security Operations Center (SOC).

SOC Analyst L1 generally focuses on monitoring security alerts, identifying suspicious activities, and performing initial analysis. L2 involves deeper investigation, incident analysis, threat hunting, and responding to more complex security incidents.

No advanced cybersecurity experience is required. Basic knowledge of networking, operating systems, cybersecurity concepts, and familiarity with Windows or Linux can be helpful. A willingness to learn and an interest in cybersecurity are recommended.

After completing the training, you will be able to monitor security alerts, analyze logs, investigate suspicious activities, identify potential threats, understand SIEM-based security monitoring, and perform basic incident response. The training can also help prepare you for entry-level SOC and cybersecurity roles.

Yes. Practical scenarios can help you understand how security alerts are investigated, analyzed, and handled in a real SOC environment.

Professional cybersecurity experience is not mandatory. However, having a basic understanding of networking, Linux/Windows systems, and cybersecurity fundamentals can make the learning process easier.

Dedicated labs, certified instructors, and placement support. You will receive guidance from trainers throughout the course, including support with practical exercises, tools and software setup, assignments, and cybersecurity concepts. You can also ask questions and get clarification during the training.

Yes. Depending on your requirements, you can discuss suitable schedules with the training team. One-to-one training and group-based learning options may also be available.

The course pricing varies depending on the subject and level. For detailed information on the course price, please contact us directly: +977-9841002000 / +977-1-4111849. Our team will be happy to guide you or send us an email at [email protected].

Our course is in hybrid training mode; you can attend in person or join online, whichever works for you. If you can't make it in person on a given day, you can simply join that class online instead.

Our syllabus outlines are only the headlines of the major modules. To ensure a complete understanding of the course, we offer free counseling. Also, if you have specific modules in mind, you can customize the course. Send your inquiry today!

  • What is a SOC?
  • SOC objectives
  • SOC functions
  • SOC organizational structure
  • L1, L2, L3 responsibilities
  • SOC Manager
  • Incident Response team
  • Threat Intelligence team
  • Detection Engineering
  • Threat Hunting
  • DFIR
  • Vulnerability Management
  • Security Engineering

  • Alert → Triage → Investigation → Escalation → Containment → Eradication → Recovery → Closure
  • Incident lifecycle
  • Case management
  • Evidence handling
  • Shift handover
  • Escalation procedures
  • Incident severity
  • SLA management

  • MTTD
  • MTTA
  • MTTR
  • False-positive rate
  • Alert volume
  • Alert-to-incident ratio
  • Escalation rate
  • Detection coverage
  • Analyst workload

  • OSI model, TCP/IP model, Ethernet, MAC addresses, IPv4, IPv6, CIDR, Subnetting, ARP, ICMP, TCP, UDP

Important protocols

  • HTTP/HTTPS, DNS, DHCP, SSH, FTP/SFTP, SMTP, IMAP, LDAP, Kerberos, SMB, RDP, SNMP, NTP, TLS

Practical labs

  • Wireshark packet analysis
  • TCP handshake analysis
  • DNS investigation and DNS query/response analysis with Wireshark
  • HTTP investigation
  • SSH traffic analysis
  • TCPdumps
  • Suspicious outbound connection investigation

  • CIA triad
  • Authentication
  • Authorization
  • Accounting AAA
  • Least privilege
  • Defense in depth
  • Zero Trust
  • Attack surface
  • Vulnerabilities
  • Exploits
  • Threats
  • Risk
  • Indicators of Compromise
  • Indicators of Attack

Windows architecture

  • Windows processes, Services, Registry, Users/groups, Security principals, ACLs, UAC, Scheduled Tasks, PowerShell, WMI, Windows Defender

Windows Event Logs

  • Security
  • System
  • Application
  • PowerShell
  • Sysmon
  • Windows Defender
  • Task Scheduler

Linux fundamentals

  • Processes
  • Services
  • systemd
  • Users
  • Groups
  • Permissions
  • Cron
  • SSH
  • /proc
  • /var/log

  • What is SIEM?
  • Log collection
  • Log parsing
  • Normalization
  • Enrichment
  • Correlation
  • Detection
  • Alerting
  • Incident management

Log sources

  • Windows
  • Linux
  • Firewall
  • IDS/IPS
  • EDR
  • Antivirus
  • VPN
  • Proxy
  • DNS
  • DHCP
  • WAF
  • Email
  • Cloud
  • Database
  • Application
  • Identity provider

  • Wazuh SIEM

Why SOC Analyst L1 & L2 Training?

Build real SOC-ready skills: Go beyond theory with hands-on labs in packet analysis, log investigation, and alert triage used daily by working analysts.
Master the SOC analyst toolkit: Get practical experience with Wireshark, Wazuh SIEM, Sysmon, Windows Event Logs, and MITRE ATT&CK, the same tools used in enterprise SOCs.
Understand attacks from both sides: Learn how threats like phishing, ransomware, sideways movement, and data leakage actually work, so you can detect and stop them before they get worse.
Handle the entire lifecycle of an incident: From alert triaging and investigation to containment, eradication, and recovery, aligned with your actual SOC workflows and SLAs.
Learn From Certified Trainers: We offer industry-vetted, certified trainers with practical lab experience to teach each concept, complemented by 100% career placement assistance from our placement teams for career readiness.
L1 to L2 Career Readiness: The program is designed with career readiness in mind to help you grow from junior (L1) responsibilities to advanced ones such as threat hunting and CTI.
Quick Inquiry

Choose class schedule(s)