Academy · VCA · SIEM & SOAR
SIEM & SOAR Engineering
The masterclass in building and operating a modern SOC stack: collecting the right telemetry, parsing and normalizing it into a common schema, engineering behavioral detections mapped to MITRE ATT&CK, and automating response with SOAR playbooks that keep a human in the loop. Written for security engineers, SOC analysts, detection engineers, and architects.
1
Telemetry & Log Management
Garbage in, garbage out.
- Syslog: What to Turn On and How to Collect ItThe foundational standard, collected so nothing is lost and nothing leaks.Free
- Windows Event Logging & WEFThe event IDs that matter, collected without an agent on every box.
- Windows Firewall Rule LoggingEast-west visibility your perimeter firewall will never give you.
2
Parsing, Normalization & Enrichment
From raw text to structured truth.
3
Detection Engineering & Threat Intel
Behaviors, not thresholds.
4
SOAR: Workflows, Automation & Response
Machine speed, human judgment.
- Orchestration vs. AutomationConnect the tools; then — carefully — remove the human.Free
- SOAR Architectural Best PracticesGuardrails first: HITL, modular playbooks, standardized output.
- Core SOAR WorkflowsTwo production-grade playbooks, walked through end to end.
- The Continuous Tuning LifecycleThe dependency chain, shadow mode, and the meltdown equation.
We're online · book a SOC walkthrough today
Earn the VCA · SIEM & SOAR
badge.
Work through every lesson and pass the module checks to earn this domain badge. Collect all eight to unlock the Vijilan Certified Defender capstone.
