Online training · 5 days · 90 academic hours
Training for SOC teams.
Five days from signal to evidence.
A 90-hour programme in information and cyber security governance for SOC teams: law and notification to NKSC, digital evidence, SOC architecture, threat intelligence and vulnerabilities, incident investigation, playbooks and SOAR, recovery and lessons learned. Each day, participants work one synthetic BALTNET case, from the first signal to a traceable conclusion.
Author: dr. Šarūnas Grigaliūnas
- 90 h
- Academic hours15 theory, 45 practical and 30 independent. Practice gets three times as much time as theory.
- 5 × BALTNET
- Training casesEvery day has its own synthetic case with logs, PCAP, IOCs and templates. No real data.
- 17 + 10
- Practical stages and labs17 core practical stages, 10 extra labs and five individual assignments ID-01–ID-05.
- ≥ 70 %
- Pass mark45 % practical, 30 % individual work, 25 % tests. A 12-question Kahoot every day.
Programme
Five days, one chain
Each day builds on the last: mandate and evidence become architecture, architecture becomes intelligence decisions, decisions become investigation and response, and response becomes recovery and lessons.
- Day 1
SOC mandate, incident notification and digital evidence
Mandate, the NIS2 24 / 72 h clock, evidence provenance and integrity.
Day plan - Day 2
Security policy and SOC technical architecture
Policy, the data path, IMS, SIEM, NIDS and HIDS.
Day plan - Day 3
SOC maturity, threat intelligence (CTI) and vulnerability management
O/P/T/P maturity, PIRs, CVSS / EPSS / KEV prioritisation and MISP.
Day plan - Day 4
Incident investigation, threat hunting, playbooks and SOAR
Triage, hypothesis-driven hunting, a playbook with human gates, a safe SOAR simulation.
Day plan - Day 5
Culture, exercises, system recovery and lessons learned
Behaviour metrics, tabletop exercises, GO / NO-GO recovery and reporting.
Day plan
Learning outcomes
What participants will be able to do
The programme prepares SOC analysts, incident management, threat intelligence and vulnerability management specialists, threat hunters and CSIRT / CERT team members.
- U01
The SOC in the organisation
Operating models, roles, responsibilities, escalation and working with the CISO, IT, management and CSIRT / CERT.
- U02
Law and regulation
NIS2 and the Lithuanian Cybersecurity Law, notification to NKSC, personal data protection and handling digital evidence.
- U03
SOC technology architecture
Designing, configuring and integrating SIEM, EDR/XDR, NDR, IDS/IPS and log management.
- U04
Vulnerabilities and threat intelligence
Prioritisation, IOC and TTP analysis, source evaluation, MISP and STIX / TAXII.
- U05
Incident investigation
Triage, log and network traffic analysis, MITRE ATT&CK, hypothesis-driven hunting and fewer false positives.
- U06
Response and recovery
Playbooks and SOAR, containment, system recovery, technical and regulatory reports, lessons learned.
How the work is done
Fact, decision, owner, deadline, evidence
The same formula repeats across all five days. Every conclusion carries a file, a record ID, a time, a justification and a next step. Another analyst must be able to repeat the investigation.
- 01
Fact
Every claim rests on a file, a record ID and a time, not on instinct or a tool's label.
- 02
Decision
What the data supports, what it does not, and what is still missing are kept apart.
- 03
Owner
Legal, technical and business decisions belong to different people, and they are named.
- 04
Deadline
The notification clock, RTO / RPO, remediation and review dates are calculated traceably.
- 05
Evidence
Work counts as done only when there is verifiable acceptance or closure evidence.
What you work with
- Security Onion 3
- Suricata
- Zeek
- Sysmon
- Wireshark
- CyberChef
- MISP
- MITRE ATT&CK
- CVSS · EPSS · KEV
- SOAR
- Kahoot
All lab data is synthetic (.example, RFC 5737). No action on production systems; isolation and SOAR actions are simulated only, behind human gates.
After the course
CISO.lt and SIEM.LT
Two projects that help carry the course outputs into your own organisation: documents and compliance with CISO.lt, threat intelligence and MISP with SIEM.LT.
CISO.lt
ciso.ltInformation security officer's assistant
An AI assistant for Lithuanian organisations: security policies and procedures, incident management plans, risk assessment, and NIS2 and GDPR compliance. In the course it helps turn the Day 1, 2 and 5 outputs into your own organisation's documents.
- Security policy and procedures
- Incident management plan and notification
- Risk assessment
- NIS2 / GDPR compliance checklists
SIEM.LT
siem.ltLocal-first threat intelligence workstation
An open-source, locally run threat intelligence workstation: MISP indicators, interactive IP geolocation, a Lithuanian news radar, and IOC export to CSV or STIX 2.1. In the course it lets you carry the Day 2–4 SIEM, CTI and MISP work into your own environment.
- MISP IOC and IP geography
- OSINT / RSS radar in Lithuanian
- IOC de-duplication and STIX 2.1 export
- Docker deployment in minutes
Manual
The SOC Officer operating manual
Reference material before and after the course: how a SOC gets its authority, how its week runs, how an incident is handled, and what the organisation must prove under NIS2 and the Lithuanian Cybersecurity Law.
The Role
What the SOC Officer is accountable for
OpenMandate
Establishing authority and scope
OpenOperating Model
Functions, tiers and cadence
OpenIncident Procedure
Detection to lessons learned
OpenCompliance
NIS2 and the Lithuanian Cybersecurity Law
OpenReporting
Reports, metrics and evidence
OpenBuild a SOC
Standing up a lean SOC
OpenKits
Instruction and help kits
Open
Ready for day one?
Before Day 1, set up a Windows 11 workstation: WinGet packages, a Python environment and a local CyberChef. The instructor provides the participant pack and the Kahoot PIN.