Skip to content
Exploit Labs
SOC-200 · OSDA · For security teams

SOC-200: what the course covers - and what we add.

SOC-200 (OSDA) trains detection and analysis: attack techniques from the defender's view, log and telemetry analysis, alert triage and escalation.

Who it is for

First and second line SOC analysts, and detection engineers early in their path.

Course content (official scope)

  • Attack techniques from the defender's view
  • Log and telemetry analysis
  • Alert triage and escalation
  • Windows and Linux artefacts

Course content, labs and the OSDA exam are provided by OffSec. The official course description always takes precedence. This page reviewed: 2026-08-07.

What Exploit Labs adds
  • +A follow-on purple teaming session where your team tests the learned techniques live against your own detection

For security teams

Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.

See Learn Enterprise

For individual practitioners

Individual licence, access duration, exam attempts and preparation - start here.

See individual licences