Academy · VCA · SIEM & SOAR
SIEM & SOAR Engineering
The masterclass in building and operating a modern SOC stack: collecting the right telemetry, parsing and normalizing it into a common schema, engineering behavioral detections mapped to MITRE ATT&CK, and automating response with SOAR playbooks that keep a human in the loop. Written for security engineers, SOC analysts, detection engineers, and architects.
1
Telemetry & Log Management
Garbage in, garbage out.
- Syslog: What to Turn On and How to Collect ItThe foundational standard, collected so nothing is lost and nothing leaks.Free
- Windows Event Logging & WEFThe event IDs that matter, collected without an agent on every box.
- Windows Firewall Rule LoggingEast-west visibility your perimeter firewall will never give you.
2
Parsing, Normalization & Enrichment
From raw text to structured truth.
3
Detection Engineering & Threat Intel
Behaviors, not thresholds.
4
SOAR: Workflows, Automation & Response
Machine speed, human judgment.
- Orchestration vs. AutomationConnect the tools; then — carefully — remove the human.Free
- SOAR Architectural Best PracticesGuardrails first: HITL, modular playbooks, standardized output.
- Core SOAR WorkflowsTwo production-grade playbooks, walked through end to end.
- The Continuous Tuning LifecycleThe dependency chain, shadow mode, and the meltdown equation.
Who does this for real
The services where Vijilan runs this work for partners and their clients.
We're online · book a SOC walkthrough today
Earn the VCA · SIEM & SOAR
badge.
Work through every lesson and pass the module checks to earn this domain badge. Collect all eight to unlock the Vijilan Certified Defender capstone.
