Train to become OSDA certified
SOC-200 (OSDA) - Security Operations and Defensive Analysis
Your ticket to professional cyber defense – practical, certified, effective
The OffSec SOC-200 teaches you the practical basics for entering a Security Operations Center (SOC). You will learn to recognize, analyze and correctly evaluate cyber attacks. Through realistic labs and scenarios, you will develop a deep understanding of attacker behavior and build the skills to reliably identify security incidents in the operational environment.
Upcoming Training Dates
| Course | Date & Location | Type & Services | Format |
|---|---|---|---|
| SOC-200 OSDA | October 27–November 19, 2026 Virtual/online Language: EN | 8 sessions of 4-hour online training Each session runs from 2:00 PM to 6:00 PM CET // 8:00 AM to 12:00 PM EST/EDT Tuesday, Oct. 27 / Nov. 3 / Nov. 10 / Nov. 17 Thursday, Oct. 29, Nov. 5, Nov. 12, and Nov. 19. | minimum 5 participants |
| SOC-200 OSDA | April, 5-9, 2027, Frankfurt Language: EN/DE | 5-day intensive training course Mon–Thu, 9 a.m.–5 p.m. CET Fri, 9 a.m.–3 p.m. CET - Meals included during the day (drinks, 2 snack breaks, 1 lunch per day) - 1 group dinner including a drink | minimum 5 participants |
Included services
Your added value with the Red & Blue Alliance
- Training with a strong practical orientation
- Individually selected OffSec license (Course & Cert, Learn One, Learn Enterprise)
- Professional team of trainers with many years of practical experience in IT security companies
- Course language English – trainers are at least bilingual (DE/EN)
- Catering included during the training days (for public face-to-face training courses)
Trainer support included – even after the course: Our Discord channel provides you with direct exchange with trainers, professional support and targeted guidance on your way to certification.
Aims of the training
SOC-200 (OSDA) – Your entry into Security Operations
- You detect and analyze cyber attacks
- You understand attacker behavior (TTPs)
- You evaluate logs and security events
- You work with SIEM systems
- You identify weak points and anomalies
Result: You are optimally prepared for your work in the SOC and can recognize and process security incidents – exactly as required in the OSDA certification.
Target group & requirements
Target group
The target group of the OffSec SOC-200 (OSDA) primarily comprises beginners and prospective specialists in the Blue Team:
- Newcomers to cyber security
- Prospective SOC Analysts (Level 1 / Junior)
- IT administrators with an interest in security operations
- Blue team-oriented specialists
The course is aimed at you if you are looking for an introduction to operational cyber security and want to learn how to recognize and analyze attacks.
Prerequisites
For the OffSec SOC-200 (OSDA), you do not need in-depth previous experience in the security sector, but a solid technical foundation is important:
- Basic knowledge of IT & networks
- Basic knowledge of Windows & Linux
- First contact with IT security (an advantage)
- Basic command line knowledge
- Analytical thinking
If you feel confident in IT basics and are interested in understanding and analyzing attacks, you are well prepared for the course.
Seminar content
Contents of the SOC-200 (OSDA)
- Attacker Methodology
: Understanding Typical Attacker Strategies (TTPs) - Windows Endpoint Security
: Analysis of Logs and Artifacts on Windows Systems - Windows Server Attacks
: Detection of Attacks on Servers and Active Directory - Windows Client Attacks
: Analysis of client-based attacks (e.g., malware, phishing) - Windows Privilege Escalation
: Detecting Privilege Escalation and Vulnerabilities - Linux Endpoint Security
: Fundamentals of Linux Logs and Processes - Linux Server Attacks
: Analysis of Typical Attacks on Linux Systems - Linux Privilege Escalation
: How to Detect Privilege Escalation Methods
Focus: Understanding attacks, recognizing traces, reacting correctly.
The right license for your requirements
With Course & Cert, Learn One and Learn Enterprise, we offer three different learning models – from targeted certification to comprehensive, scalable training. The following overview shows the most important differences at a glance.
Course & Cert
The classic entry option for a single course.
- 1 course + certification
- 90 days Lab access
- 1 examination attempt
- Download the course materials
Ideal for you if you want to prepare specifically for certification
👉 In short: focused, affordable, but not very flexible
Learn One
Your annual subscription with significantly more options.
- 1 200 or 300 level course + certification
- 365 days Lab access
- 2 exam attempts
- Access to exercise environments, challenge labs and learning paths
- Download the course materials
Ideal for you if you want to build up several skills or broaden your base
👉 In short: flexible, comprehensive, highly practice-oriented
Learn Enterprise
The corporate solution for structured team training.
- Unlimited choice of courses
- 6 examination attempts/certification per year
- 365 days Lab access
- Central management of users, progress and licenses
- Reporting & analytics for training progress
- Individual learning paths for different roles (e.g. SOC, Pentest, Blue Team)
- Scalable for larger teams or entire departments
👉 In short: scalable, controllable, ideal for strategic training
