SOC-200 · OSDA · For security teams
SOC-200: what the course covers - and what we add.
SOC-200 (OSDA) trains detection and analysis: attack techniques from the defender's view, log and telemetry analysis, alert triage and escalation.
Who it is for
First and second line SOC analysts, and detection engineers early in their path.
Course content (official scope)
- →Attack techniques from the defender's view
- →Log and telemetry analysis
- →Alert triage and escalation
- →Windows and Linux artefacts
Course content, labs and the OSDA exam are provided by OffSec. The official course description always takes precedence. This page reviewed: 2026-08-07.
What Exploit Labs adds
- +A follow-on purple teaming session where your team tests the learned techniques live against your own detection
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseFor individual practitioners
Individual licence, access duration, exam attempts and preparation - start here.
See individual licences