Train to become OSDA certified

SOC-200 (OSDA) - Security Operations and Defensive Analysis

Your ticket to professional cyber defense – practical, certified, effective

The OffSec SOC-200 teaches you the practical basics for entering a Security Operations Center (SOC). You will learn to recognize, analyze and correctly evaluate cyber attacks. Through realistic labs and scenarios, you will develop a deep understanding of attacker behavior and build the skills to reliably identify security incidents in the operational environment.

Upcoming Training Dates

CourseDate & LocationType & ServicesFormat
SOC-200 OSDAOctober 27–November 19, 2026
Virtual/online
Language: EN
8 sessions of 4-hour online training
Each session runs from 2:00 PM to 6:00 PM CET // 8:00 AM to 12:00 PM EST/EDT
Tuesday, Oct. 27 / Nov. 3 / Nov. 10 / Nov. 17
Thursday, Oct. 29, Nov. 5, Nov. 12, and Nov. 19.
minimum 5 participants
SOC-200 OSDAApril, 5-9, 2027, Frankfurt
Language: EN/DE
5-day intensive training course
Mon–Thu, 9 a.m.–5 p.m. CET
Fri, 9 a.m.–3 p.m. CET
- Meals included during the day (drinks, 2 snack breaks, 1 lunch per day)
- 1 group dinner including a drink
minimum 5 participants

Included services

Your added value with the Red & Blue Alliance

  • Training with a strong practical orientation
  • Individually selected OffSec license (Course & Cert, Learn One, Learn Enterprise)
  • Professional team of trainers with many years of practical experience in IT security companies
  • Course language English – trainers are at least bilingual (DE/EN)
  • Catering included during the training days (for public face-to-face training courses)
  • Trainer support included – even after the course: Our Discord channel provides you with direct exchange with trainers, professional support and targeted guidance on your way to certification.

Aims of the training

SOC-200 (OSDA) – Your entry into Security Operations

  • You detect and analyze cyber attacks
  • You understand attacker behavior (TTPs)
  • You evaluate logs and security events
  • You work with SIEM systems
  • You identify weak points and anomalies

Result: You are optimally prepared for your work in the SOC and can recognize and process security incidents – exactly as required in the OSDA certification.

Target group & requirements

Target group

The target group of the OffSec SOC-200 (OSDA) primarily comprises beginners and prospective specialists in the Blue Team:

  • Newcomers to cyber security
  • Prospective SOC Analysts (Level 1 / Junior)
  • IT administrators with an interest in security operations
  • Blue team-oriented specialists

The course is aimed at you if you are looking for an introduction to operational cyber security and want to learn how to recognize and analyze attacks.

Prerequisites

For the OffSec SOC-200 (OSDA), you do not need in-depth previous experience in the security sector, but a solid technical foundation is important:

  • Basic knowledge of IT & networks
  • Basic knowledge of Windows & Linux
  • First contact with IT security (an advantage)
  • Basic command line knowledge
  • Analytical thinking

If you feel confident in IT basics and are interested in understanding and analyzing attacks, you are well prepared for the course.

Seminar content

Contents of the SOC-200 (OSDA)

  • Attacker Methodology
    : Understanding Typical Attacker Strategies (TTPs)
  • Windows Endpoint Security
    : Analysis of Logs and Artifacts on Windows Systems
  • Windows Server Attacks
    : Detection of Attacks on Servers and Active Directory
  • Windows Client Attacks
    : Analysis of client-based attacks (e.g., malware, phishing)
  • Windows Privilege Escalation
    : Detecting Privilege Escalation and Vulnerabilities
  • Linux Endpoint Security
    : Fundamentals of Linux Logs and Processes
  • Linux Server Attacks
    : Analysis of Typical Attacks on Linux Systems
  • Linux Privilege Escalation
    : How to Detect Privilege Escalation Methods

Focus: Understanding attacks, recognizing traces, reacting correctly.

The right license for your requirements

With Course & Cert, Learn One and Learn Enterprise, we offer three different learning models – from targeted certification to comprehensive, scalable training. The following overview shows the most important differences at a glance.

Course & Cert

The classic entry option for a single course.

  • 1 course + certification
  • 90 days Lab access
  • 1 examination attempt
  • Download the course materials

Ideal for you if you want to prepare specifically for certification

👉 In short: focused, affordable, but not very flexible

Learn One

Your annual subscription with significantly more options.

  • 1 200 or 300 level course + certification
  • 365 days Lab access
  • 2 exam attempts
  • Access to exercise environments, challenge labs and learning paths
  • Download the course materials

Ideal for you if you want to build up several skills or broaden your base

👉 In short: flexible, comprehensive, highly practice-oriented

Learn Enterprise

The corporate solution for structured team training.

  • Unlimited choice of courses
  • 6 examination attempts/certification per year
  • 365 days Lab access
  • Central management of users, progress and licenses
  • Reporting & analytics for training progress
  • Individual learning paths for different roles (e.g. SOC, Pentest, Blue Team)
  • Scalable for larger teams or entire departments

👉 In short: scalable, controllable, ideal for strategic training

Fancy more?

Find the training course that suits you!