
SOC-200 — Foundational Defensive Operations & Analysis (OSDA)
OffSec's blue-team flagship.
SOC-200 trains defenders the way OSCP trains attackers — fully hands-on, with a 24-hour practical exam. Macksofy's bootcamp covers Splunk, Elastic, Sysmon and EDR triage in real-world scenarios.
What is the OSDA certification?
The Offensive Security Defense Analyst (OSDA, OffSec) certifies blue-team detection skills — using SIEM and telemetry to detect and analyse attacks across the kill chain. Macksofy runs an OSDA (SOC-200) exam-prep bootcamp with live detection labs in India.
Outcomes — concrete, measurable.
Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.
- Detect attacker TTPs across Windows, Linux and ADDefensive·Foundational60%
- Use EDRs and SIEMs to investigate live incidentsCapability·Practitioner77%
- Pass the 24-hour OSDA (SOC-200) examCapability·Specialist94%
- Capability2
- Defensive1
- SOC Analyst Tier-3₹15–22 LPA3–5 years
- Detection Engineer₹15–25 LPA3–5 years
- Threat Hunter₹18–28 LPA4+ years
Is SOC-200 / OSDA right for you?
- SOC analysts (Tier-2/3)
- Threat hunters
- Incident responders
What we assume you know
- Basic Windows/Linux administration
- Networking fundamentals
19 modules. 60-day OffSec lab + 24-hour exam.
Search modules and topics, and switch between Split and Track views to see how every module flows into the next.
Module 01 · Attacker Methodology Introduction
- 01Cyber Kill Chain & MITRE ATT&CK alignment
- 02Pyramid of Pain
- 03Common attacker tradecraft overview
Module 02 · Windows Endpoint Introduction
- 01Windows architecture for defenders
- 02Sysmon configuration (industry-standard ruleset)
- 03Key event IDs (4624, 4625, 4688, 4720, 7045, 4732)
Module 03 · Windows Server-Side Attacks
- 01Detecting brute-force & password spraying
- 02RDP / SMB / WinRM abuse detection
- 03Service-creation indicators
Module 04 · Windows Client-Side Attacks
- 01Office macro detection
- 02PowerShell-based attack indicators
- 03ScriptBlock & Module logging
Module 05 · Windows Privilege Escalation
- 01Token-impersonation indicators
- 02Service-misconfiguration abuse signals
- 03UAC bypass detection
Module 06 · Windows Persistence
- 01Run-keys, scheduled tasks, services
- 02WMI subscriptions
- 03DLL search-order hijacking detection
Module 07 · Windows Credentials
- 01LSASS access detection
- 02Mimikatz indicators
- 03DPAPI / Credential Guard considerations
Module 08 · Windows Lateral Movement
- 01WinRM, WMI, PsExec, smbexec, dcomexec indicators
- 02Pass-the-hash detection
- 03Remote-service-creation signals
Module 09 · Active Directory Enumeration & Attacks
- 01BloodHound query indicators
- 02Kerberoast / AS-REP roast detection
- 03DCSync detection
Module 10 · Linux Endpoint Introduction
- 01auditd configuration
- 02syslog & journald analysis
- 03Bash-history forensics
Module 11 · Linux Server-Side Attacks
- 01SSH brute-force & key-abuse detection
- 02Web-app attack signals on Linux
- 03Container runtime indicators
Module 12 · Linux Privilege Escalation
- 01SUID / sudo abuse detection
- 02Cron-job tampering signals
- 03Kernel-exploit indicators
Module 13 · Network Detections
- 01IDS / IPS — Suricata & Zeek
- 02Network-flow analysis
- 03Beaconing detection
Module 14 · Antivirus Alerts and Evasion
- 01Triaging EDR alerts
- 02Detecting AMSI / ETW patching
- 03Custom-payload identification
Module 15 · Active Directory Persistence
- 01Golden / silver tickets
- 02DCShadow detection
- 03AdminSDHolder modifications
Module 16 · SIEM Part One — Intro to ELK
- 01Logstash filter writing
- 02Elasticsearch index design
- 03Kibana visualisation & dashboards
Module 17 · SIEM Part Two — Combining the Logs
- 01Cross-source correlation
- 02Sigma rule writing
- 03Alert tuning workflow
Module 18 · Trying Harder — The Labs
- 01End-to-end OSDA-style investigation
- 0224-hour exam strategy
- 03Reporting per OffSec defensive standards
Macksofy bootcamp · Real-world IR playbooks
- 01Phishing IR (Macksofy case)
- 02Ransomware IR (Macksofy case)
- 03Cloud incident IR (AWS / Azure)
The same toolkit our consultants use on real engagements.
Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.
What roles open up after you complete this.
| Role | Salary band | Experience |
|---|---|---|
| SOC Analyst Tier-3 | ₹15–22 LPA | 3–5 years |
| Detection Engineer | ₹15–25 LPA | 3–5 years |
| Threat Hunter | ₹18–28 LPA | 4+ years |
We don’t promise jobs. We open doors.
Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.
- 1:1 resume + LinkedIn rewrite with our hiring desk
- Mock interviews with active practitioners
- Direct intros to BFSI, fintech and Big-4 partners
- UAE placement support (Dubai, Abu Dhabi)
Things students ask before enrolling.

OSWA — Foundational Web Application Assessments (WEB-200)
Foundational web pentest credential — black box.

OSWP — Foundational Wireless Network Attacks (PEN-210)
Master Wi-Fi attacks. Earn OSWP.

OSCC — CyberCore Security Essentials (SEC-100)
OffSec's entry point into the cybersecurity career stack.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
