SOC-200 Offensive Security का defensive security certification है जो Offensive Security Defense Analyst (OSDA) credential देता है। यह course L1 SOC analyst से L2/L3 advanced detection engineer में grow करने वालों के लिए ideal है। Macksofy की 10-सप्ताह की हिंदी मेंटर-लेड बूटकैंप में MITRE ATT&CK framework, advanced SIEM use cases, threat hunting methodology, और detection-as-code practices सब हिंदी में सिखाए जाते हैं। Macksofy OffSec का Authorized Training Partner नहीं है; यह independent prep program है OSDA exam के लिए।
SOC-200 हिंदी में क्यों करें?
OSDA credential Indian SOC market में premium signal है — L2/L3 SOC analyst roles, threat hunter positions, और detection engineering jobs के लिए preferred credential। Mumbai BFSI, Bangalore product security teams, और Hyderabad MSSPs (DXC, Tech Mahindra) OSDA-certified analysts को CTC premium देते हैं। CSA L1 → SOC-200 L2 progression typical career path है 18-24 महीने के experience के बाद।
Course curriculum और structure
SOC-200 हिंदी बूटकैंप की कुल अवधि 10 सप्ताह है। हर सप्ताह में लाइव mentor-led sessions, hands-on lab assignments, और peer cohort study groups शामिल हैं। Cohort delivery mode: online (live Zoom-based) या BKC Mumbai classroom (in-person)। दोनों cohort simultaneously चलते हैं, और आप कभी भी online ↔ classroom switch कर सकते हैं batch duration के दौरान।
Tools और lab environment
हिंदी बूटकैंप में आप industry-standard tools पर hands-on training पाएँगे: Splunk Enterprise Security, Elastic Stack, Sigma rules, MITRE ATT&CK Navigator, Atomic Red Team, Caldera, Velociraptor, OSQuery, KAPE, Yara, Sysmon, Wazuh। Lab environment Macksofy द्वारा internally host की गई है और cohort duration भर unlimited access के साथ आती है। हर lab session में हिंदी में step-by-step mentor walkthrough और bilingual lab manual provided है।
Prerequisites — क्या background ज़रूरी है?
1+ साल का SOC L1 experience या CSA equivalent। Linux command-line fluency, SIEM basic usage, और MITRE ATT&CK familiarity required। CompTIA Security+ या CSA certification preferred entry filter है।
Career outcomes और salary expectations (2026)
OSDA-certified L2 SOC Analyst CTC India में ₹10–16 LPA Indian MSSPs और BFSI captives में, और ₹14–22 LPA Foreign bank cyber-engineering teams और Big 4 advanced SOC practices में। 3–5 साल experience के बाद Threat Hunter / Detection Engineer roles में ₹20–32 LPA। SOC Architect और Detection Lead positions ₹30–45 LPA cross करती हैं।
Cohort calendar — 2026–27
- Online हिंदी बैच: 2026-10-12 → 2026-12-21
- BKC classroom हिंदी बैच: 2026-10-26 → 2027-01-04
- अगला online cohort: 2027-02-01 → 2027-04-12
Fees, EMI, और payment options
SOC-200 cohort fees: ₹70,000 (online), ₹95,000 (BKC classroom)। दोनों options पर 0% EMI HDFC, ICICI, Axis, SBI, और Kotak credit cards पर (3, 6, 9, या 12 महीने)। Corporate sponsorship के लिए GST invoice Macksofy Technologies Pvt Ltd (GSTIN 27AALCM7641P1ZA) से issue होती है।
Enrollment कैसे करें?
Email करें services@macksofy.com पर अपना target course (SOC-200), current experience level, और language preference के साथ। या call करें +91 9930824239 पर। हम 1 working day में cohort readiness assessment और next 3 cohort start dates के साथ reply करते हैं।
Related: सभी Hindi-medium cybersecurity courses देखें | English version of SOC-200 course | Mumbai placement program
10 सप्ताह का सप्ताह-दर-सप्ताह सिलेबस
नीचे SOC-200 (OSDA) हिंदी बूटकैंप का हफ़्तेवार breakdown है। हर हफ़्ते live mentor session, hands-on detection lab और cohort review होती है।
- सप्ताह 1 — SOC fundamentals — security operations model, alert triage lifecycle, escalation paths, shift handover discipline
- सप्ताह 2 — Windows endpoint attack surface और Windows Event Logs — कौन सा Event ID असल में मायने रखता है
- सप्ताह 3 — Linux endpoint attack surface, auditd और syslog — Linux telemetry पढ़ना
- सप्ताह 4 — Network detection fundamentals — traffic analysis, beaconing patterns, DNS और proxy logs
- सप्ताह 5 — MITRE ATT&CK framework — technique mapping और detection strategy बनाना
- सप्ताह 6 — SIEM deep dive — search language, correlation rules, dashboards, alert quality metrics
- सप्ताह 7 — Detection engineering — Sigma rules, detection-as-code workflow, false-positive tuning
- सप्ताह 8 — Active Directory attack detection — Kerberoasting, DCSync, lateral movement के footprints
- सप्ताह 9 — Threat hunting methodology — hypothesis-driven hunts, IOC बनाम behaviour-based hunting
- सप्ताह 10 — Incident response workflow, analyst report writing + पूरा exam simulation
OSDA exam का format — क्या उम्मीद करें
SOC-200 का exam भी पूरी तरह practical है। आपको एक simulated enterprise environment दिया जाता है जिसमें attacker activity हुई है, और लगभग 24 घंटे के hands-on exam में आपको उस activity को detect, analyse और document करना होता है — यानी logs और telemetry से attack chain reconstruct करनी होती है। उसके बाद अलग window में detailed analyst report submit करनी होती है।
यहाँ सबसे बड़ा फ़र्क़ यह है कि offensive exams में आप exploit चलाते हैं, जबकि यहाँ आपको evidence से कहानी बनानी होती है — कौन सा alert किस technique से जुड़ा है, किस host पर पहले क्या हुआ, और आप यह किस log line से साबित कर रहे हैं। इसलिए हमारे cohort में हर lab के साथ documentation अनिवार्य है। Exact scoring rules OffSec बदलता रहता है, इसलिए registration से पहले official exam guide verify करें।
रोज़ाना तैयारी का roadmap
- Weekdays (2–3 घंटे): 1 घंटा concept, 1–2 घंटे उसी technique का detection lab
- Weekends (5–7 घंटे): पूरी attack chain end-to-end detect करें और लिखें
- हर lab के बाद: अपनी detection logic को Sigma rule की तरह लिखकर रखें
- हफ़्ते में एक बार: Atomic Red Team से technique simulate करके अपनी ही detection test करें
- आख़िरी 2 हफ़्ते: full-length mock exam + analyst report, असली exam conditions में
6 आम गलतियाँ जो SOC-200 aspirants करते हैं
- Alert triage को rote बना देना — हर alert पर hypothesis बनाना सीखें, checklist भरना काफ़ी नहीं
- Baseline समझे बिना rules लिखना — normal क्या है यह जाने बिना anomaly पकड़ना असंभव है
- False-positive tuning ignore करना — जो rule 500 alerts रोज़ देता है, उसे SOC कुछ ही दिन में mute कर देता है
- ATT&CK technique IDs रट लेना — ID याद होना बेकार है अगर उसकी detection logic समझ न आए
- सिर्फ़ SIEM UI पर निर्भर रहना — raw log पढ़ना आना चाहिए, वरना parsing गड़बड़ होते ही आप अंधे हो जाते हैं
- Documentation skip करना — OSDA exam में report ही आपका असली deliverable है
हिंदी medium — फ़ायदे और limitations (ईमानदारी से)
हमारी teaching का माध्यम हिंदी है, लेकिन आपको यह साफ़ पता होना चाहिए कि OffSec का official course material, lab interface, exam और final report — ये सब English में ही हैं। हिंदी cohort का मक़सद यह है कि concepts (networking, privilege escalation, detection logic) आप अपनी भाषा में तेज़ी से और गहराई से समझ सकें, doubts बिना झिझक पूछ सकें, और peer discussion comfortable रहे। लेकिन tool output पढ़ना, documentation follow करना और exam report English में लिखना आपको आना ही चाहिए। इसलिए हर cohort में हम technical English reading और report writing साथ-साथ build कराते हैं — हिंदी को crutch नहीं, on-ramp की तरह इस्तेमाल करते हैं।
एक और बात साफ़ कर दें: Macksofy Splunk के vendor certifications, Microsoft SC-200, GIAC GCIH या BTL1 offer नहीं करता। हमारा SOC-200 cohort इन exams की तैयारी नहीं है। हम detection engineering के vendor-neutral fundamentals पढ़ाते हैं (labs में Splunk और Elastic दोनों use होते हैं), जो इन सभी platforms पर transfer होते हैं।
ज़रूरी सूचना: यह पेज केवल शैक्षणिक जानकारी के लिए है। यहाँ बताई गई सभी security techniques केवल उन्हीं systems पर इस्तेमाल करें जिनके लिए आपके पास written authorization हो — बिना अनुमति testing करना भारत में IT Act के तहत अपराध है। ऊपर दी गई salary ranges market estimates हैं जो role, city, experience और employer के अनुसार काफ़ी बदलती हैं; ये किसी employment या salary की guarantee नहीं हैं। Certification exam OffSec द्वारा संचालित की जाती है — Macksofy एक independent exam-prep provider है, OffSec का Authorized Training Partner नहीं।
अक्सर पूछे जाने वाले प्रश्न (FAQs)
प्रश्न 1: क्या Macksofy OffSec का Authorized Training Partner (ATP) है?
नहीं — Macksofy OffSec ATP नहीं है। यह independent mentor-led prep program है OffSec की official SOC-200 / OSDA exam के लिए।
प्रश्न 2: OSDA exam क्या है और कितना मुश्किल है?
OSDA OffSec का 24-घंटे का practical exam है जहाँ आपको adversary attacks detect करने हैं, log analysis से evidence निकालनी है, और structured incident report submit करना है। यह hands-on exam है — multiple-choice नहीं।
प्रश्न 3: क्या CSA या CompTIA Security+ के बिना SOC-200 कर सकते हैं?
Possible है लेकिन difficult। हम recommend करते हैं कि आपके पास 1+ साल SOC L1 experience हो या CSA/Security+ foundational background हो। बिना foundation के SOC-200 advanced concepts struggle करा सकते हैं।
प्रश्न 4: Splunk vs Elastic — कौन सा सीखाया जाता है?
दोनों — Macksofy की cohort में पहले 4 weeks Elastic SIEM (open-source advantage), अगले 4 weeks Splunk Enterprise Security, और last 2 weeks dual-platform threat hunting exercises।
प्रश्न 5: Career के लिए OSCP या SOC-200 — क्या लेना चाहिए?
यह आपके career direction पर depends। Offensive security / pentest career के लिए OSCP। Defensive security / SOC / threat hunting career के लिए SOC-200। Both को combine करना senior-level positions (Purple Team, Detection Engineer-Pentester hybrid) के लिए strong combination है।
प्रश्न 6: SOC-200 की तैयारी के लिए रोज़ कितने घंटे देने चाहिए?
Weekdays पर 2–3 घंटे और weekends पर 5–7 घंटे, 10 हफ़्तों तक — यह ज़्यादातर working SOC analysts के लिए realistic है। चूँकि course L1 experience मानकर चलता है, concept time कम और hands-on detection lab time ज़्यादा रखें।
प्रश्न 7: क्या बिना SOC experience के SOC-200 कर सकते हैं?
सीधे नहीं — SOC-200 L1 analyst से L2/L3 की तरफ़ बढ़ने वालों के लिए design किया गया है। अगर आपके पास SOC experience नहीं है तो पहले CompTIA Security+ या Certified SOC Analyst (CSA) जैसा foundation program करें, कुछ महीने triage का काम करें, फिर SOC-200 join करें।
प्रश्न 8: कौन सा SIEM सिखाया जाता है — Splunk या Microsoft Sentinel?
हमारे labs में मुख्य रूप से Splunk और Elastic Stack इस्तेमाल होते हैं, और हम detection logic को vendor-neutral तरीक़े से पढ़ाते हैं ताकि वह Sentinel (KQL) पर भी लागू हो। ध्यान रहे: Macksofy Splunk के official vendor certifications या Microsoft SC-200 की तैयारी नहीं कराता।
प्रश्न 9: OSDA, CySA+ और CSA में क्या फ़र्क़ है?
CSA और CompTIA CySA+ मुख्यतः knowledge-based हैं और L1/early-L2 analysts के लिए अच्छे entry credentials हैं। OSDA पूरी तरह hands-on practical exam है जिसमें आपको असली telemetry से attack chain detect करके document करनी होती है — इसीलिए detection-engineering roles में यह ज़्यादा weight रखता है। कई candidates CSA → OSDA का रास्ता लेते हैं।
प्रश्न 10: SOC-200 के बाद कौन सी job roles मिल सकती हैं?
आम तौर पर L2/L3 SOC Analyst, Threat Hunter, Detection Engineer और Incident Responder जैसी roles। पूरा defensive career path, हर rung की skills और realistic timeline समझने के लिए हमारी गाइड How to Become a SOC Analyst in India 2026 पढ़ें।
हिंदी में और कोर्स / More Macksofy courses in Hindi




