
Intermediate toAdvanced
SOC Analysts
Equip SOC Analysts with foundational and advanced understanding of Gen AI (Generative AI) and LLMs (Large Language Models) in cybersecurity.
Mastering Gen AI Tools for SOC Analysts
| Module | Curriculum |
|---|---|
|
1.1 Introduction to AI and Machine Learning in Cybersecurity
|
|
| Module 1 Foundations of AI & LLMs for Cybersecurity |
1.2 Understanding LLMs (Large Language Models)
|
|
1.3 Common Issues and Limitations
|
|
| Module 2 AI for Cybersecurity vs. Cybersecurity for AI |
2.1 Securing AI Systems
|
|
2.2 Applying AI for Security Operations
|
|
|
3.1 Offensive AI Techniques
|
|
| Module 3 Threat Actor Use of AI |
3.2 Real-World Scenarios and Labs
|
|
Hands-On Lab:
|
|
|
4.1 Practical AI Applications in SOC
|
|
| Module 4 Advanced SOC & IR Use Cases |
4.2 Extended Use Cases
|
|
Hands-On Lab:
|
|
|
5.1 Threat Intelligence with AI
|
|
| Module 5 Threat Actor Use of AI |
5.2 Compliance Monitoring and Reporting
|
|
5.3 Building AI Agents & Automated Workflows
|
Training Goals





Frequently Asked Questions
This training is ideal for SOC analysts, cybersecurity engineers, researchers, red-teamers, and AI-curious security professionals aiming to integrate real-world AI tools and agentic systems into their operational environments.
The training covers LLM foundations, cloud vs local deployment, prompt engineering, AI red teaming, deepfake/phishing simulation, SOC automation (log parsing, playbook generation), threat intelligence clustering, compliance automation, and building AI agents using tools like n8n, Tracecat, and LLMStudio.
The core program spans 2 intensive day, structured into 5 modules with theory and hands-on labs. Participants can revisit content asynchronously, with full access to resources and lab environments.
Free for SOCRadar Customers, Partners, and the First 99 Applicants!
Absolutely. Every module includes lab sessions—such as deploying LLMs locally, crafting phishing emails with AI, generating IR playbooks, simulating prompt injections, parsing logs, and building multi-agent security workflows using real tools like LLMStudio, WormGPT, and Tracecat.
SOCRadar’s threat intel feeds, CVE insights, and brand monitoring data can be integrated into GenAI workflows using techniques covered in the training (like RAG, IOC enrichment, and automated bot monitoring), making threat detection and reporting even more contextual and actionable.
Yes. A certificate of completion is issued after participants complete the hands-on labs and key modules, which can be used to validate AI literacy in cybersecurity operations and shared on professional platforms.
















