Cybersecurity 路 Free

SOC Analyst Level 2: Threat Hunting with Wazuh

Level 2 SOC skills in a free, open source lab: build a Wazuh 4.14 server, enrol Windows and Linux agents with Sysmon, write and tune detection rules, map them to MITRE ATT&CK, hunt persistence, credential access and lateral movement, handle incidents with NIST SP 800-61 Rev. 3, and measure your detections against an Atomic Red Team simulation in an isolated lab.

14 modules 13h 59m of video English 路 self-paced

Inside the course

SOC Analyst Level 2: Threat Hunting with Wazuh: Syllabus at a glanceSOC Analyst Level 2: Threat Hunting with Wazuh: What you will be able to doSOC Analyst Level 2: Threat Hunting with Wazuh: Tools and credits

From the lessons

  • Wazuh 101: What is Wazuh?

    From L1 triage to L2 hunting: the job and the lab plan

    MyDFIR

  • Build a SOC Lab with Wazuh: Connect Agents + Sysmon (Part 2)

    Enrolling Windows and Linux agents, with Sysmon

    MyDFIR

  • Build a SOC Lab with Wazuh: Generate + Read Telemetry (Part 3)

    Telemetry, decoders and reading events in Wazuh

    MyDFIR

  • Security Snippets: Detection Engineering with MITRE ATT&CK

    MITRE ATT&CK for detection coverage

    Anvilogic

  • How to Discover Windows Run Key Persistence When Threat Hunting

    Hunting persistence and credential access

    Insane Cyber

  • Build a SOC Lab with Wazuh: File Integrity Monitor + Rules (Part 5)

    File integrity monitoring, vulnerability detection and active response

    MyDFIR

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Explain how Level 2 work differs from Level 1 triage; deploy a Wazuh server and enrol Windows and Linux agents; configure Sysmon for hunting; write custom decoders and test events with wazuh-logtest; write, test and tune Wazuh rules with sensible levels, correlation and narrow exceptions; tag detections with MITRE ATT&CK v19 and measure coverage; run and record hypothesis-driven hunts for persistence, LSASS access and lateral movement; use file integrity monitoring, vulnerability detection and active response safely; handle an incident on the NIST SP 800-61 Rev. 3 model and write the report; and score detection coverage with an Atomic Red Team simulation in your own isolated lab.

  • Know what Level 2 SOC work adds to Level 1 triage, and build a safe, isolated hunting lab
  • Install Wazuh 4.14, enrol Windows and Linux agents and troubleshoot them
  • Configure and tune Sysmon for the events hunters rely on
  • Write decoders and custom Wazuh rules with correlation, levels and narrow exceptions
  • Tag detections with MITRE ATT&CK v19 and measure coverage in Navigator
  • Run hypothesis-driven hunts for persistence, LSASS access and lateral movement
  • Use file integrity monitoring, vulnerability detection and active response safely
  • Handle and report incidents with NIST SP 800-61 Rev. 3, and score detections against an Atomic Red Team simulation

For you

Taking SOC Analyst Level 2: Threat Hunting with Wazuh from the United States

The course project 路 about 12 hours

L2 hunt for a managed security provider: hunt plan, lab simulation, detection pack, incident report and coverage report

Act as the Level 2 analyst at a small managed security provider onboarding a new client. In your own isolated Wazuh lab, plan three ATT&CK-based hunts, have a partner run an Atomic Red Team simulation, hunt it blind, write the detections that were missing, report the incident on the NIST SP 800-61 Rev. 3 model, and measure detection coverage before and after. The sample pack shows each document filled in for a worked example.

Sample document pack, 5 documents, filled in for the scenario

  • PlanHunt plan: client onboarding, ransomware precursors
  • Test reportAtomic Red Team simulation record (isolated lab)
  • RegisterDetection register: custom Wazuh rules after the hunt
  • ReportIncident report: simulated intrusion on LAB-WIN11
  • ReportDetection coverage report: before and after the hunt

Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.

Course content

14 modules 路 39 lessons 路 13h 59m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.

  1. 01From L1 triage to L2 hunting: the job and the lab plan24m
  2. 02Wazuh architecture and a working server56m
  3. 03Enrolling Windows and Linux agents, with Sysmon30m
  4. 04Sysmon configuration for hunting45m
  5. 05Telemetry, decoders and reading events in Wazuh1h 11m
  6. 06Detection rules: writing, testing and tuning1h 50m
  7. 07MITRE ATT&CK for detection coverage1h 6m
  8. 08Hypothesis-driven threat hunting1h 6m

Requirements

Who it is for
Intermediate. For Level 1 SOC analysts, IT and network administrators and security graduates who already triage alerts and read Windows event logs. Comfort with the Linux command line, basic networking and virtual machines is expected; SOC Analyst Level 1 with Splunk covers the foundations.
Software
Wazuh 4.14 (free and open source), Microsoft Sysmon (free), Atomic Red Team with Invoke-AtomicRedTeam (free, lab use only), MITRE ATT&CK Navigator (free, in the browser), a Windows 11 evaluation VM, Ubuntu Server, and VirtualBox or Docker. What to download, and how
Hardware
A computer with 16 GB of RAM and about 150 GB of free disk for the Wazuh server and two small VMs, or a free-tier cloud account kept private to you. The lab must stay isolated from any work or third-party network.

Software you need

What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.

Everything runs on virtual machines you own, on a host-only or NAT network with no route to other networks. Docker is an alternative way to run the Wazuh server. Atomic Red Team is for the isolated lab only.

Required

  1. 01

    Wazuh (server, indexer, dashboard and agents)

    Wazuh Inc. (open source project)

    Free
    Runs on
    Server: 64-bit Linux (x86_64 or ARM64) such as Ubuntu 22.04 or 24.04; agents for Windows, Linux and macOS
    Account
    None needed
    Size
    Quickstart for 1 to 25 agents: 4 vCPU, 8 GiB RAM, 50 GB storage for 90 days of data

    Wazuh is free and open source (GPL version 2 and Apache 2.0 components). Wazuh Inc. sells an optional cloud service and support, which the course does not need.

    Official download pagedocumentation.wazuh.com
  2. 02

    Sysmon (System Monitor)

    Microsoft Sysinternals

    Free
    Runs on
    Windows 11 and Windows Server 2019 or later (Microsoft's page); Sysmon for Linux is a separate project
    Account
    None needed
    Size
    2.8 MB download (Microsoft's page)

    Free under the Sysinternals software licence terms, which you accept at install with -accepteula.

    Official download pagelearn.microsoft.com
  3. 03

    Windows 11 Enterprise (evaluation)

    Microsoft

    Free trial: 90 days
    Runs on
    Installs as a virtual machine or on a PC; ISO for x64 and Arm64
    Account
    A short registration form on the Microsoft Evaluation Center

    A full-featured 90-day evaluation for testing, with no product key needed. When it expires the desktop turns black, a notice stays on screen and the PC shuts down every hour.

  4. 04

    Ubuntu Desktop

    Canonical

    Free
    Runs on
    64-bit PC (Intel or AMD) or ARM 64-bit. Recommended: 2 GHz dual-core processor, 6 GB RAM, 25 GB free disk space.
    Account
    None needed
    Size
    About 5.9 GB ISO (Intel or AMD 64-bit, current LTS)

    Free to download and use. LTS releases get five years of free security updates, which Ubuntu Pro can extend.

    Alternatives

  5. 05

    Oracle VirtualBox

    Oracle

    Free
    Runs on
    Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
    Account
    None needed

    The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.

Optional

Useful, not needed to finish the course.

  1. 06

    Docker Desktop

    Docker, Inc.

    Free for personal use, education and small businesses
    Runs on
    Windows 10 64-bit version 22H2 (build 19045) or Windows 11 64-bit version 23H2 (build 22631) or later, with WSL 2 and hardware virtualisation on, 8 GB RAM. Also macOS and Linux.
    Account
    None needed

    Free for personal use, education, non-commercial open source projects, and businesses with fewer than 250 employees and less than 10 million US dollars in annual revenue. Larger businesses need a paid subscription. Docker Engine on Linux is open source and is not covered by these terms.

    Alternatives

    • Docker Engine (Linux): Free, open source engine for Linux. Not covered by the Docker Desktop subscription terms.
  2. 07

    Atomic Red Team and Invoke-AtomicRedTeam

    Red Canary (open source project)

    Free
    Runs on
    Windows, Linux and macOS test definitions; Invoke-AtomicRedTeam runs in PowerShell
    Account
    None needed

    MIT licence. The tests change real system state and must be run only on lab machines you own, isolated from other networks.

  3. 08

    MITRE ATT&CK Navigator

    The MITRE Corporation, in the browser

    Free
    Runs on
    Any modern web browser
    Account
    None needed

    Free to use; ATT&CK content is published by MITRE under its terms of use.

    Open MITRE ATT&CK Navigatormitre-attack.github.io

Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.

SOC Analyst Level 2: Threat Hunting with Wazuh at a glance

SOC Analyst Level 2: Threat Hunting with Wazuh is a free, self-paced online course from EDWartens for level 1 SOC analysts, IT administrators and security graduates moving into Level 2 investigation, threat hunting and detection work. It has 14 modules and 13h 59m of video lessons by MyDFIR, Wazuh, John Hammond and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.

All course facts
Price
Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
Who it is for
Level 1 SOC analysts, IT administrators and security graduates moving into Level 2 investigation, threat hunting and detection work
Format
14 self-paced modules, 13h 59m of video, written notes, a practice task per module and one final assessment.
Level
Intermediate. Intermediate. For Level 1 SOC analysts, IT and network administrators and security graduates who already triage alerts and read Windows event logs. Comfort with the Linux command line, basic networking and virtual machines is expected; SOC Analyst Level 1 with Splunk covers the foundations.
Brand
Vendor-neutral
Software
Wazuh 4.14 (free and open source), Microsoft Sysmon (free), Atomic Red Team with Invoke-AtomicRedTeam (free, lab use only), MITRE ATT&CK Navigator (free, in the browser), a Windows 11 evaluation VM, Ubuntu Server, and VirtualBox or Docker.
Hardware
A computer with 16 GB of RAM and about 150 GB of free disk for the Wazuh server and two small VMs, or a free-tier cloud account kept private to you. The lab must stay isolated from any work or third-party network.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
MyDFIR, Wazuh, John Hammond, Insane Cyber, Anvilogic, HackerSploit, Prabh Nair, Mohd Maaz, Christian Lempa, Taylor Walton, Misk Samater, Red Canary, RJC, Tech with Jono, SecGen, InfoSec Pandey, ANOMALI, p1p0, HyperQube, Karissa Ehman, Security BSides London (independent creators, credited below)
Language
English
Last updated
27 September 2026

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

Pairs well with

More free courses: Free cyber security courses

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of SOC Analyst Level 2: Threat Hunting with Wazuh, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

What is a SOC Analyst Level 2 and what does this course teach?

A Level 2 SOC analyst takes escalated alerts from Level 1, works out how far an attack reaches, recommends containment, hunts for activity no rule has caught and writes or tunes detections. This course teaches that work hands-on with Wazuh, Sysmon and MITRE ATT&CK, from building the lab to writing an incident report.

Who is this Wazuh threat hunting course for, and what do I need first?

It is for Level 1 SOC analysts, IT and network administrators and security graduates who already triage alerts and can read Windows event logs. You should be comfortable with the Linux command line, basic networking and virtual machines; SOC Analyst Level 1 with Splunk on EDWartens covers the foundations.

Is Wazuh free, and what software does the course use?

Yes, Wazuh is free and open source, and so is everything else the course needs: Microsoft Sysmon, Atomic Red Team, MITRE ATT&CK Navigator, Ubuntu, a Windows 11 evaluation VM and VirtualBox or Docker. The course uses Wazuh 4.14, the current release line in October 2026.

Is the lab safe and legal?

Yes, provided you follow the course rules: everything runs on virtual machines you own, on a network with no route to your employer's or anyone else's systems, and attack simulations with Atomic Red Team run only inside that isolated lab from a snapshot you revert afterwards. The course never asks you to test a system you do not own.

How long does the course take, and is it free to learn?

It takes about 20 hours at your own pace, of which about 14 hours is video, plus about 12 hours for the optional project. Every module, the notes, the 156 practice questions, the project and the final assessment are free to learn.

What certificate do I get, and how is it verified?

You get an EDWartens verifiable certificate of completion when you finish the modules and pass the 15-question final at 60 percent. It carries a unique certificate number and a QR code that open a public verification page showing the course, the modules covered and your final score.

Which frameworks and standards does the course follow?

Detections are mapped to MITRE ATT&CK v19, including the April 2026 split of Defense Evasion into Stealth and Defense Impairment, and incident handling follows NIST SP 800-61 Rev. 3, which builds incident response on the six CSF 2.0 Functions. The course is not affiliated with Wazuh Inc., MITRE, NIST or Red Canary.

What jobs can this course lead to?

It prepares you for SOC analyst Level 2, threat hunter, detection engineer and incident responder roles, and for SOC work at managed security providers that run Wazuh for their clients. Managed security providers, banks, telecoms and IT services firms run 24x7 SOCs and look for analysts who can show hands-on hunting and detection work, such as the project in this course.

What you walk away with

Your certificate for SOC Analyst Level 2: Threat Hunting with Wazuh

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for SOC Analyst Level 2: Threat Hunting with Wazuh
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

  • Adds to LinkedIn in one click

  • QR code on the certificate

  • Names what you can do

  • A permanent link

  • Earned, not attended

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.

Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

  • MyDFIRWazuh 101, the seven-part Build a SOC Lab with Wazuh series (server, agents and Sysmon, telemetry, dashboard, file integrity monitoring and rules, active response, the investigation), the Sysmon installation tutorial and a real account compromise investigation
  • Wazuhthe project's own webinars on detection as code and on simulating attacks with Atomic Red Team and analysing them with Wazuh and Sysmon
  • John Hammonddetection engineering with Wazuh and testing defences with Atomic Red Team
  • Insane Cyberwriting Sysmon rules and hunting Run key persistence, malicious scheduled tasks, malicious account use and network share use in Windows logs
  • Anvilogicdetection engineering with MITRE ATT&CK and lateral movement in Windows networks
  • HackerSploitmapping threat group techniques with MITRE ATT&CK Navigator
  • Prabh Nairpractical threat hunting with Sysmon and MITRE ATT&CK
  • Mohd MaazSysmon event IDs 1, 3, 10, 17 and 18 for blue team detection
  • Christian Lempadeploying Wazuh with Docker in a home lab
  • Taylor Waltonbuilding custom Wazuh decoders
  • Misk SamaterWazuh vulnerability detection and configuration assessment
  • Red Canarywhat Atomic Red Team is and how security teams use it
  • RJCthe differences between Tier 1, Tier 2 and Tier 3 SOC analysts
  • Tech with Jonothe path from beginner to Level 3 SOC analyst
  • SecGena Wazuh detection engineering lab writing SSH attack detection rules
  • InfoSec Pandeymapping detection rules to MITRE ATT&CK
  • ANOMALIhypothesis-led threat hunting
  • p1p0detecting credential dumping from Mimikatz to the SIEM
  • HyperQubecredential dumping analysis, detection and prevention
  • Karissa Ehmancyber incident response and the updates in NIST SP 800-61 Rev. 3
  • Security BSides LondonHan O'Connor's talk on investigation note-taking and report writing for SOC analysts

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.