Skip to content

Online training · 5 days · 90 academic hours

Training for SOC teams.
Five days from signal to evidence.

A 90-hour programme in information and cyber security governance for SOC teams: law and notification to NKSC, digital evidence, SOC architecture, threat intelligence and vulnerabilities, incident investigation, playbooks and SOAR, recovery and lessons learned. Each day, participants work one synthetic BALTNET case, from the first signal to a traceable conclusion.

Author: dr. Šarūnas Grigaliūnas

Related tools:ciso.ltsiem.lt

90 h
Academic hours15 theory, 45 practical and 30 independent. Practice gets three times as much time as theory.
5 × BALTNET
Training casesEvery day has its own synthetic case with logs, PCAP, IOCs and templates. No real data.
17 + 10
Practical stages and labs17 core practical stages, 10 extra labs and five individual assignments ID-01–ID-05.
≥ 70 %
Pass mark45 % practical, 30 % individual work, 25 % tests. A 12-question Kahoot every day.

Learning outcomes

What participants will be able to do

The programme prepares SOC analysts, incident management, threat intelligence and vulnerability management specialists, threat hunters and CSIRT / CERT team members.

Full programme and assessment
  • U01

    The SOC in the organisation

    Operating models, roles, responsibilities, escalation and working with the CISO, IT, management and CSIRT / CERT.

  • U02

    Law and regulation

    NIS2 and the Lithuanian Cybersecurity Law, notification to NKSC, personal data protection and handling digital evidence.

  • U03

    SOC technology architecture

    Designing, configuring and integrating SIEM, EDR/XDR, NDR, IDS/IPS and log management.

  • U04

    Vulnerabilities and threat intelligence

    Prioritisation, IOC and TTP analysis, source evaluation, MISP and STIX / TAXII.

  • U05

    Incident investigation

    Triage, log and network traffic analysis, MITRE ATT&CK, hypothesis-driven hunting and fewer false positives.

  • U06

    Response and recovery

    Playbooks and SOAR, containment, system recovery, technical and regulatory reports, lessons learned.

How the work is done

Fact, decision, owner, deadline, evidence

The same formula repeats across all five days. Every conclusion carries a file, a record ID, a time, a justification and a next step. Another analyst must be able to repeat the investigation.

  1. 01

    Fact

    Every claim rests on a file, a record ID and a time, not on instinct or a tool's label.

  2. 02

    Decision

    What the data supports, what it does not, and what is still missing are kept apart.

  3. 03

    Owner

    Legal, technical and business decisions belong to different people, and they are named.

  4. 04

    Deadline

    The notification clock, RTO / RPO, remediation and review dates are calculated traceably.

  5. 05

    Evidence

    Work counts as done only when there is verifiable acceptance or closure evidence.

What you work with

  • Security Onion 3
  • Suricata
  • Zeek
  • Sysmon
  • Wireshark
  • CyberChef
  • MISP
  • MITRE ATT&CK
  • CVSS · EPSS · KEV
  • SOAR
  • Kahoot

All lab data is synthetic (.example, RFC 5737). No action on production systems; isolation and SOAR actions are simulated only, behind human gates.

After the course

CISO.lt and SIEM.LT

Two projects that help carry the course outputs into your own organisation: documents and compliance with CISO.lt, threat intelligence and MISP with SIEM.LT.

  • CISO.lt

    ciso.lt

    Information security officer's assistant

    An AI assistant for Lithuanian organisations: security policies and procedures, incident management plans, risk assessment, and NIS2 and GDPR compliance. In the course it helps turn the Day 1, 2 and 5 outputs into your own organisation's documents.

    • Security policy and procedures
    • Incident management plan and notification
    • Risk assessment
    • NIS2 / GDPR compliance checklists
  • SIEM.LT

    siem.lt

    Local-first threat intelligence workstation

    An open-source, locally run threat intelligence workstation: MISP indicators, interactive IP geolocation, a Lithuanian news radar, and IOC export to CSV or STIX 2.1. In the course it lets you carry the Day 2–4 SIEM, CTI and MISP work into your own environment.

    • MISP IOC and IP geography
    • OSINT / RSS radar in Lithuanian
    • IOC de-duplication and STIX 2.1 export
    • Docker deployment in minutes

Manual

The SOC Officer operating manual

Reference material before and after the course: how a SOC gets its authority, how its week runs, how an incident is handled, and what the organisation must prove under NIS2 and the Lithuanian Cybersecurity Law.

Ready for day one?

Before Day 1, set up a Windows 11 workstation: WinGet packages, a Python environment and a local CyberChef. The instructor provides the participant pack and the Kahoot PIN.