SEC450: SANS London September 2025
Provided by SANS
What You Will Learn
The Blueprint for SOC Analyst Excellence
SEC450 is a course designed from the ground up to be the most comprehensive SOC analyst training course available. If you are working in cyber defense operations, building a SOC, or want to improve the SOC you already with better data, workflow, and analysis technique, SEC450 is the course for you! By providing a detailed explanation of the mission and mindset of a modern cyber defense operation, this course will jumpstart and empower those on their way to becoming the next generation of blue team members. With six days of training, six course books, twenty hands-on labs, and an all-day Defend the Flag Capstone competition, there is simply no other offering on the market as complete as SEC450 for SOC and security analyst training.
What You Will Learn
If you're looking for the gold standard in cyber security analyst training, you've found it! SANS SEC450 and the accompanying GIAC GSOC certification are the premier pairing for anyone looking for a comprehensive security operations training course and certification. Check out the extensive syllabus and description below for a detailed run down of course content and don't miss the free demo available by clicking the "Course Demo" button!
Designed for teams of all types, SEC450 will get you hands-on with the tools and techniques required to quickly detect and halt advanced cyberattacks! Whether you are a part of a full SOC in a large enterprise, a small security ops group, or an MSSP protecting your customers, SEC450 will teach you and your team the critical skills for understanding how to defend a modern organization.
Designed By Security Analysts, For Security Analysts
SEC450 is authored, designed, and advised by a group of veteran SOC analysts and managers to be a one-stop shop for all the essential techniques, tools, and data your team will need to be effective, including:
Business Takeaways
This course will provide:
Unmatched in the industry with its volume and depth, SEC450 includes:
What You Will Receive
Depending on your current role or future plans, one of these courses is a great next step in your cybersecurity journey:
The Blueprint for SOC Analyst Excellence
SEC450 is a course designed from the ground up to be the most comprehensive SOC analyst training course available. If you are working in cyber defense operations, building a SOC, or want to improve the SOC you already with better data, workflow, and analysis technique, SEC450 is the course for you! By providing a detailed explanation of the mission and mindset of a modern cyber defense operation, this course will jumpstart and empower those on their way to becoming the next generation of blue team members. With six days of training, six course books, twenty hands-on labs, and an all-day Defend the Flag Capstone competition, there is simply no other offering on the market as complete as SEC450 for SOC and security analyst training.
What You Will Learn
If you're looking for the gold standard in cyber security analyst training, you've found it! SANS SEC450 and the accompanying GIAC GSOC certification are the premier pairing for anyone looking for a comprehensive security operations training course and certification. Check out the extensive syllabus and description below for a detailed run down of course content and don't miss the free demo available by clicking the "Course Demo" button!
Designed for teams of all types, SEC450 will get you hands-on with the tools and techniques required to quickly detect and halt advanced cyberattacks! Whether you are a part of a full SOC in a large enterprise, a small security ops group, or an MSSP protecting your customers, SEC450 will teach you and your team the critical skills for understanding how to defend a modern organization.
Designed By Security Analysts, For Security Analysts
SEC450 is authored, designed, and advised by a group of veteran SOC analysts and managers to be a one-stop shop for all the essential techniques, tools, and data your team will need to be effective, including:
- Security Data Collection - How to make the most of security telemetry including endpoint, network, and cloud-based sensors
- Automation - How to identify the best opportunities for SOAR platform and other script-based automation
- Efficient Security Process - How to keep your security operations tempo on track with in-depth discussions on what a SOC or security operations team should be doing at every step from data generation to detection, triage, analysis, and incident response
- Quality Triage and Analysis - How to quickly identify and separate typical commodity attack alerts from high-risk, high-impact advanced attacks, and how to do careful, thorough, and cognitive-bias free security incident analysis
- False Positive Reduction - Detailed explanations, processes, and techniques to reduce false positives to a minimum
- SOC Tools - including hands-on exercises demonstrating:
- How to collect, organize, and use relevant threat data in a Threat Intelligence Platform (TIP)
- Principles of success for endpoint security data collection whether you use a SIEM, EDR, or XDR
- Alert Triage - How to quickly and accurately triage security incidents, using clever data correlation and enrichment techniques that will immediately surface and sort true positives from false positives
- How to best use incident management systems to effectively analyze, document, track, and extract critical metrics from your security incidents
- Crafting automation workflows for common SOC activities, relieving analysts of boring tasks and freeing up time for better threat hunting and detection engineering
- Burnout and Turnover Reduction - Informed with both scientific research and years of personal experience, this class teaches what causes cyber security analyst burnout and how you and your team can avoid it by understanding the causes and factors that lead to burnout. This class will help you build a long-term sustainable cyber defense career so you and your team can deliver the best every day!
- Certification - The ability to add on the GIAC GSOC certification that encourages students to retain the material over the long term, and helps you objectively demonstrate you and your team's level of skill
Business Takeaways
This course will provide:
- A turn-key solution for SOC analyst training needs - giving analysts the skills they need to understand the tools, data, and defensive priorities required to defend your network from high-impact cyber attacks
- How to derive clear strategic priorities for your security operations team
- Show you how to make the most of security telemetry including endpoint, network, and cloud-based sensors
- A battle-tested method to reduce false positives to the lowest possible level
- The techniques for quick and accurate security incident triage
- The methods to improve the effectiveness, efficiency, and impact of your SOC
Unmatched in the industry with its volume and depth, SEC450 includes:
- 1300 pages of instructional content and labs with extensive notes and documentation
- 20 hands-on exercises putting real SOC tools and situations in front of students to emphasize lessons with a virtual workbook containing extra challenges to test your understanding of the material
- A custom course Linux virtual machine filled with real SOC tools
- A capture-the-flag contest experience for students to apply their new knowledge and put their analysis skills to the test!
- Continuously updated material to cover the newest attackers and techniques
What You Will Receive
- Custom distribution of the Linux Virtual Machine containing a pre-built simulated SOC environment
- MP3 audio files of the complete course lecture
- Introduction and walk-through videos of labs
- Digital Download Package that includes the above and more
Depending on your current role or future plans, one of these courses is a great next step in your cybersecurity journey:
- SOC Analyst
- SEC503: Network Monitoring and Threat Detection In-Depth
- SEC504: Hacker Tools, Techniques, and Incident Handling
- Security Architect or Engineer
- SEC511: Cybersecurity Engineering: Advanced Threat Detection and Monitoring
- SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise
- SOC Lead or Manager
- LDR551: Building and Leading Security Operations Centers
- LDR512: Security Leadership Essentials for Managers
Enquire
Start date | Location / delivery | |
---|---|---|
08 Sep 2025 | London | Book now |