Skip to content
Macksofy Technologies
SOC-200 — Foundational Defensive Operations & Analysis (OSDA)
OffSec
SOC-200 / OSDA
Hands-on certification bootcamp
SOC-200 / OSDAIntermediate

SOC-200 — Foundational Defensive Operations & Analysis (OSDA)

OffSec's blue-team flagship.

SOC-200 trains defenders the way OSCP trains attackers — fully hands-on, with a 24-hour practical exam. Macksofy's bootcamp covers Splunk, Elastic, Sysmon and EDR triage in real-world scenarios.

60-day OffSec lab + 24-hour exam 19 modules Hybrid · Macksofy mentorship + OffSec course
In short

What is the OSDA certification?

The Offensive Security Defense Analyst (OSDA, OffSec) certifies blue-team detection skills — using SIEM and telemetry to detect and analyse attacks across the kill chain. Macksofy runs an OSDA (SOC-200) exam-prep bootcamp with live detection labs in India.

What you’ll be able to do

Outcomes — concrete, measurable.

Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.

Capability Profile
  • Detect attacker TTPs across Windows, Linux and AD
    Defensive·Foundational
    60%
  • Use EDRs and SIEMs to investigate live incidents
    Capability·Practitioner
    77%
  • Pass the 24-hour OSDA (SOC-200) exam
    Capability·Specialist
    94%
Capability Mix
  • Capability
    2
  • Defensive
    1
Roles & salary bands
  • SOC Analyst Tier-3
    ₹15–22 LPA
    3–5 years
  • Detection Engineer
    ₹15–25 LPA
    3–5 years
  • Threat Hunter
    ₹18–28 LPA
    4+ years
Who it’s for

Is SOC-200 / OSDA right for you?

  • SOC analysts (Tier-2/3)
  • Threat hunters
  • Incident responders
Before you start

What we assume you know

  • Basic Windows/Linux administration
  • Networking fundamentals
Curriculum

19 modules. 60-day OffSec lab + 24-hour exam.

Search modules and topics, and switch between Split and Track views to see how every module flows into the next.

Modules
19
Topics
57
Module 01 / 19 · SOC-200 / OSDA

Module 01 · Attacker Methodology Introduction

  • 01
    Cyber Kill Chain & MITRE ATT&CK alignment
  • 02
    Pyramid of Pain
  • 03
    Common attacker tradecraft overview
Tools you’ll operate

The same toolkit our consultants use on real engagements.

Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.

Tooling stack
SplunkElastic StackSysmonSigmaMITRE ATT&CK NavigatorVelociraptor
Career outcomes

What roles open up after you complete this.

RoleSalary bandExperience
SOC Analyst Tier-3₹15–22 LPA3–5 years
Detection Engineer₹15–25 LPA3–5 years
Threat Hunter₹18–28 LPA4+ years
Placement support

We don’t promise jobs. We open doors.

Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.

  • 1:1 resume + LinkedIn rewrite with our hiring desk
  • Mock interviews with active practitioners
  • Direct intros to BFSI, fintech and Big-4 partners
  • UAE placement support (Dubai, Abu Dhabi)
FAQ

Things students ask before enrolling.

OffSec SOC-200 + 60-day lab + exam bundle is ~₹1,70,000. Through Macksofy the same official bundle — course, 60-day lab and exam voucher — is ₹1,45,000 (15% off, EMI available). The Macksofy bootcamp with real-world IR playbooks (phishing, ransomware, cloud) and mentor support is a separate add-on, quoted on top.
SOC-200 is significantly more advanced than CSA (EC-Council). Think of CSA as a starter exam and SOC-200 as the elite blue-team cert with a 24-hour hands-on practical — analogous to what OSCP+ is for offence.
CySA+ (CompTIA) is broad and DoD-compliant — strong for government / DoD-adjacent roles. CSA (EC-Council) is entry-level SOC. SOC-200 (OSDA) is the only blue-team cert with a 24-hour practical exam — strongest signal for senior detection-engineering roles. Many SOC L3 candidates hold all three.
Yes — labs run on a real Splunk Enterprise + Elastic Stack environment with Sysmon-instrumented Windows endpoints, Velociraptor for live response and Sigma rules for detection engineering.
24-hour proctored hands-on exam: you investigate a simulated incident across multiple endpoints + a SIEM, identify attacker TTPs (mapped to MITRE ATT&CK) and write a professional defensive report. Macksofy includes one full mock 24-hour exam.
SOC Analyst Tier-3 (₹15–22 LPA at 3–5 years), Detection Engineer (₹15–25 LPA), Threat Hunter (₹18–28 LPA), Incident Responder (₹15–25 LPA). Common employers: Indian BFSI SOCs (HDFC, Kotak, ICICI), Big-4 MDR/MSSP teams, K7, Quick Heal, ADCB / Mashreq SOCs in UAE.
Yes if your goal is senior detection / threat-hunting work. CSA and Security+ are knowledge exams; OSDA is a hands-on practical that proves you can investigate live incidents. The two stack well on a CV.
Common paths: GIAC GCFA / GREM for advanced forensics + malware reversing, GIAC GCDA for detection-engineering depth, or pivoting to threat intelligence (CTIA, GCTI). Macksofy mentors all three.
Yes — live online SOC-200 cohorts pan-India and corporate blue-team batches delivered on-site at SOCs in Delhi, Bengaluru, Hyderabad, Pune, Chennai, Gurugram and Dubai.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements