MYDFIR SOC Investigation Cohort
6-Week Live Cohort

SOC Investigation
Cohort

Stop learning about investigations. Learn how to investigate.

When someone asks you to walk them through how you would investigate a scenario, can you explain what you would do, why you would do it, and defend your decisions?

Six weeks of investigations, direct feedback, challenged reasoning and reporting. Every week you progress from an example investigation, to a guided investigation, to a case you own and defend.

Apply to See If You’re a Fit

A few quick questions when you book, so I know where you are before we talk.

Live Training Begins November 7 Enrollment Closes November 1

I am only accepting a maximum of 30 people, because I need to personally review your work, question your reasoning, and give meaningful feedback.

Investigate

Work through investigations where you decide what to do next.

Get Feedback

Direct feedback on your reasoning, scope, findings, and conclusions.

Write Reports

Turn your investigation into a clear, defensible report.

Defend Your Thinking

Explain each decision and the evidence behind your conclusion.

When they ask

"Walk me through how you would investigate this."

When that moment comes, can you show how you think?

You cannot control how difficult the job market is, or who else is in the room.

You can control how prepared you are when someone finally gives you the opportunity.

  • Explain your thought process clearly
  • Know what you are trying to determine
  • Identify the evidence that matters
  • Pivot when the evidence changes
  • Scope beyond the original alert
  • Write and defend your conclusions

The Investigation Gap

You have learned cybersecurity. Now can you show how you investigate?

Before

  • "Where do I even start?"
  • "What should I investigate next?"
  • "I think this is malicious."
  • "I hope they do not question me."
  • "Do I actually know how to do this?"

After

  • "Here is what I am trying to determine first."
  • "Here is the question I need to answer next."
  • "Here is my conclusion and the evidence supporting it."
  • "I can explain why I made each decision."
  • "Give me the scenario. I will walk you through it."

Stop Trying To Figure This Out Alone

You do not need another list of things to study.

  • The environment is ready.You do not need to build another lab before you can practice.
  • The deadlines are set.You know exactly what you need to work on each week.
  • Your work gets reviewed.You do not have to wonder whether you missed something.
  • Your reasoning gets challenged.You find the gaps before an interviewer or a senior analyst does.

I remove the unnecessary friction. You focus on the investigation.

The MYDFIR Method

Everything in the cohort comes back to the same three responsibilities.

1 Investigate

Follow the evidence

Set the objective, ask the right questions, follow the evidence, scope what happened, and reach a conclusion the evidence supports.

2 Report

Explain what happened

Turn the investigation into a clear account of what happened, what you concluded, what you cannot conclude, and why it matters.

3 Defend

Stand behind it

Explain your decisions, answer questions about your scope and evidence, and stand behind what the evidence supports.

InvestigateReportDefend

How You Learn It

Every week runs the same way.

1 Example

Example Investigation

We walk through a realistic case using the investigation framework so you can see how the objective, questions, evidence, pivots, scope, and conclusion fit together.

2 Guided

Guided Investigation

We tackle the alert together in the console. You follow along in your own environment while we decide what questions to answer, where to look next, what to pivot on, and what the evidence supports.

3 Independent

Independent Investigation

You take ownership of a new alert with no walkthrough telling you what comes next. You investigate it yourself, write the report, and defend your conclusion.

ExampleGuidedIndependent

Each week, we walk through the framework, tackle an alert together, then you apply it independently. As the cohort progresses I expect more from your reasoning and give you less to lean on.

Across six weeks you will investigate scenarios spanning Email, Endpoint, Identity, Active Directory, Cloud, Linux, and more.

You will not become a better investigator by only learning how investigations should work.

You will investigate.

You will make decisions.

You will get stuck.

I will challenge your reasoning.

You will get direct feedback.

You will write and defend your findings.

I will expect more from you every week.

The goal is not to memorize the right answer. It is to learn how to find it.

What You'll Get

Realistic Investigation Environment

A purpose-built business environment where the users, systems and telemetry carry across your investigations, with scenarios built to make you investigate instead of follow instructions.

Direct Feedback

Meaningful feedback on your reasoning, scope, evidence, reports, and conclusions.

Reporting Practice

Turn findings into clear reports that expose the gaps in your own reasoning.

Challenged Reasoning

Be questioned on what you decided, why you stopped, and what could change your conclusion.

Confidence Through Proof

Confidence from repeatedly proving you can work an investigation, not from being told to feel it.

Work You Can Show

Keep the reports and capstone work you produce so you can speak to your investigation process, decisions, and growth.

From the Community

From members I have trained. The First Investigation Cohort will begin on November 7th.

"Steven helped me put all this theoretical knowledge and labs together to truly understand what happens behind the hood and how to build an investigation."
David G.
"I didn't know how to triage or investigate an alert before. Now I'm fairly confident triaging and investigating an alert using Splunk or Sentinel and providing a report."
Srinivas G.
Steven, founder of MYDFIR
Meet Steven

I built the investigation training I wish I had when I started.

I have spent over a decade in cybersecurity, mainly across security operations and DFIR.

When I started as a Tier 1 SOC analyst I got very little training, and I constantly questioned whether I was investigating things correctly.

I turned down an opportunity to move up because I did not trust my own investigative ability.

Over time I put in the reps, learned from mistakes, trained other analysts, and became someone who could step into a situation and work through the evidence.

This cohort is built around the deliberate practice, scrutiny, and feedback I wish I had early on.

Cohort Details

Onboarding Week
November 1 to 6
Access, prerequisites, setup
Live Training
November 7 to December 13
Six weeks
Schedule
Sat and Sun, 9am to 2pm ET
Wednesday Report Reviews & Defenses
Capstone
Week 6
Capacity
30
Recordings
Every Session

For aspiring and current SOC analysts who already have some cybersecurity foundation and are ready to focus specifically on becoming stronger investigators.

Who This Is For

This may be a fit if

  • You are an aspiring or current SOC analyst
  • You have already spent time learning cybersecurity fundamentals
  • You understand SOC concepts but still question your ability to investigate independently
  • You want direct feedback on your actual work
  • You are willing to be questioned and challenged
  • You are comfortable working an investigation on your own every week
  • You are able to invest in a premium hands-on training experience

This is not for you if

  • You want a broad beginner cybersecurity bootcamp
  • You want passive video training
  • You want someone to give you the answer immediately
  • You are looking primarily for offensive security training
  • You are unwilling to complete investigations and receive critical feedback
  • You are looking for free training

Apply for the Cohort

A short call to work out whether the cohort solves the problem you actually have. If it does not, I will tell you.

No available slots? Check back tomorrow.

I open my calendar 7 days at a time, and spots fill up fast. A new day opens every morning, so more times are always coming. If you don't see one that works today, set a reminder on your phone and check back tomorrow.

Enrollment closes November 1. Booking a call does not mean you have been accepted into the cohort. I read your answers beforehand, and if it is clearly not the right fit I will let you know before the call so we do not waste your time.

Before You Apply

I don't see any open times. Is the cohort full?

No. My calendar only shows the next 7 days, so it is not a waitlist and it is not sold out. Times get booked quickly, but a new day opens every morning.

Check back tomorrow and you should see fresh times. Enrollment closes November 1, so there is still room before then.

What is the schedule?

Onboarding week runs November 1 to 6. Enrollment closes November 1 and your access opens the same day, so that week is for prerequisites, environment access and setup checks. Nobody loses a training session to setup problems.

Live training runs November 7 to December 13. Six weeks.

Live training begins Saturday November 7 and runs six weeks. Sessions are Saturday and Sunday, 9am to 2pm Eastern, and I extend the hours when a session needs it. Wednesdays are live report reviews and defenses on the work you submitted that week.

Training weekends are Nov 7/8, 14/15, 21/22, 28/29, Dec 5/6 and 12/13.

Week 6 is your capstone investigation.

On top of the live sessions you work investigations between them. That is where most of the learning happens, so if you are not going to do that work you will not get much out of this.

What time zone are the sessions in?

Everything is hosted in Eastern Time. Sessions run 9am to 2pm ET, which works comfortably across the Americas, the UK, Europe, Africa and the Middle East.

If you are in Asia or Oceania it will be late at night or overnight your time. I would rather you knew that before you book than find out on the call.

Do I need a certification?

No. What matters is that you have done enough learning that investigation ability is now the thing holding you back.

Do I need a powerful computer or a home lab?

No. All you need is a browser and an internet connection.

I already work in a SOC. Is this still worth it?

It can be. Plenty of working analysts can run a process but want to get sharper on scoping, timelines, reporting, and holding their position when someone questions the finding.

What if I miss a session?

Sessions are recorded so you can catch up on the content. Your report review and defense happen live, which is why attendance matters.

Can I add these to my portfolio?

Yes and no. Every investigation you conduct except for the capstone, you may add to your portfolio and share them on LinkedIn!

The interview should not be the first time someone challenges how you investigate.

You cannot control the job market.

You cannot control who else applies.

You cannot control when your next opportunity comes.

You can control how prepared you are when it does.