SOC-200: Foundational Security Operations and Defensive Analysis - on the way to OSDA.
SOC-200 (OSDA) shows attacks from the defender's seat: what traces common techniques leave, how they surface in SIEM data, and how to separate real attacks from noise.

- Certification
- OSDA - OffSec Defense Analyst
- Level
- Intermediate
- Discipline
- Defend
- Audience
- For security teams
Who this course is for
SOC analysts, detection engineers and teams who want to understand attacks rather than only clear alerts.
Not the right course yet if
- -You want to attack rather than detect - go to PEN-200
- →Recognise attack techniques from their telemetry traces
- →Prioritise and escalate alerts defensibly
- →Turn findings into durable detection rules
- ·Windows and Linux fundamentals
- ·Some exposure to logs or a SIEM
Not sure whether you meet them? We run a short placement conversation before you buy.
What SOC-200 covers.
- Attack techniques from the defensive side
- Windows and Linux telemetry
- SIEM analysis and correlation
Course content, labs and the OSDA exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
A lab with realistic telemetry: attacks are executed and you analyse the resulting data.
Exam and credential
Practical exam analysing live attacks, with a report. Passing awards the OSDA certification.
The packages that include SOC-200.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +A follow-on purple teaming session where your team tests the learned techniques live against your own detection
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapNo, the lab provides the environment. Mapping it to your own SIEM happens in mentoring.
SOC teams that must evidence detection quality - for example under NIS2 or DORA.
Not sure whether SOC-200 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more