Certifications / Aegis

Aegis findsthe signal.

Adaptive, experiential skill acquisition for SOC analysts—inside a living operation shaped by incidents, deadlines and uncertainty.

Explore AegisAsk about enrollment
  • Online
  • 25 days
  • Performance-based
01 / The program

A realistic CSOC simulation

Work the operation—not a collection of exercises.

Aegis is a dynamic online program built for SOC analysts. For 25 days, participants work inside a realistic corporate network and confront tasks that reflect operational life.

The Scrum framework makes time management, prioritization and decision-making part of the assessment. Random incidents test readiness and resilience by introducing the pressure, ambiguity and interruptions that define real cybersecurity operations.

The certification is the first step in the Aegis, Alpha and Ranger pathway. It establishes an interdisciplinary baseline for SOC analysts and threat hunters by connecting defensive investigation, offensive context and strategic thinking.

I highly recommend the Aegis Certification because it prepares analysts for one of the SOC’s greatest challenges: working miracles in limited time and under intense pressure. The content was strong, the labs were engaging and the examination was challenging. Candidates need dedication, focus, motivation and a willingness to leave their comfort zone.
Burak GuleryuzSOC Analyst, IBM
02 / Certification coverage

Three connected dimensions

See the attack. Read the evidence. Lead the response.

Aegis connects monitoring and incident handling with offensive experimentation and the human skills required to operate under pressure.

  1. 01

    Continuous SOC operations

    Security monitoring, threat detection and incident handling continue around the clock inside a living CSOC environment. Participants work with SIEM platforms such as IBM QRadar, ELK and Splunk rather than isolated capture-the-flag exercises.

  2. 02

    Offensive context

    Linux and Windows systems form an Active Directory environment where participants conduct attacks, observe their own activity in the logs, and use the evidence to test and improve SIEM rules.

  3. 03

    Operational human skills

    A corporate storyline, task management, backlogs, daily stand-ups, retrospectives and five-day sprints develop prioritization, communication, decision-making and resilience under pressure.

We appreciate technology, but we believe in peopleWe appreciate technology, but we believe in people

03 / Operating model

Eight operating principles

Readiness emerges through accountable execution.

The program replaces passive instruction with work that must be prioritized, delivered, evaluated and improved inside a changing environment.

  1. 01

    Fully performance-based

    Work inside a small, living environment that includes SIEM, EDR, Active Directory and other SOC capabilities instead of completing disconnected exercises.

  2. 02

    Task-oriented flow

    Manage exercises, assignments and submissions through a task system. Every sprint begins with work that must be evaluated, prioritized and delivered.

  3. 03

    Incident and uncertainty

    Random incidents develop mental resilience, incident focus, reactive capability and the determination to continue when conditions change unexpectedly.

  4. 04

    Stay agile

    Run your own Scrum process, organize backlogs around weekly tasks and due dates, and strengthen project-management and decision-making skills.

  5. 05

    Adaptive and experiential

    Develop use cases, write rules and build correlations while responding to incidents in a dynamic environment shaped by pressure and uncertainty.

  6. 06

    Growth through failure

    Replace passive course material with real tasks, independent research and accountable execution. Mistakes become evidence for reflection and growth.

  7. 07

    Discipline equals freedom

    Intensive scenarios reinforce prioritization, planning, extreme ownership, persistence and the ability to learn while operating through failure.

  8. 08

    Continuous evaluation

    Mentors and an AI-supported engine evaluate task submissions and provide comments whenever additional feedback is needed.

04 / A day in Aegis
Aegis daily operational process

A living analyst workflow

Routine work can become an incident at any moment.

A participant’s day resembles that of an analyst in a heavily targeted security operations center. Periodic transitions between routine work and unexpected incidents develop adaptability, pressure-tested judgment, planning and resilience.

  1. 01

    Daily routine

    Evaluate the previous day, record challenges, decisions, feelings and solutions, then plan the work ahead.

  2. 02

    Prioritize the backlog

    Review assigned work and due dates, then make deliberate decisions about priority, effort and timing.

  3. 03

    Execute analyst tasks

    Hunt unknown threats, analyze malware, tune SIEM rules, create correlations, investigate false positives and review indicators of compromise.

  4. 04

    Respond to uncertainty

    When the command-and-control engine launches an internal, external or APT-style incident, stop routine work and focus on root cause, impact and incident management.

Enabled by S46

One system for tasks, labs, incidents and support.

S46 Simulation Software manages the full certification process. After enrollment, participants receive their account, guides and instructions for accessing the operational environment.

S46 simulation software dashboard
Cyber Struggle Aegis emblem
05 / Outcomes

Aegis holders can

Turn telemetry into an operational decision.

  • Write basic scripts that support SOC processes.
  • Identify and eliminate false positives.
  • Recognize common post-exploitation techniques and lateral movement.
  • Build correlations and write rules based on MITRE ATT&CK techniques.
  • Connect offensive techniques with investigation and detection evidence.
  • Perform root-cause, malware, network-traffic and memory analysis.
  • Develop practical working knowledge of the MITRE ATT&CK framework.
  • Maintain stronger performance under pressure.
  • Improve prioritization, time management and decision-making.
06 / Enrollment

Foundations and commitment

No prior certification. No passive participation.

Candidates need basic scripting, networking and common-service knowledge, familiarity with SIEM and logging concepts, and fundamental Linux and Windows skills. Motivation, dedication and discipline are equally important.

25 days

Five operational sprints

Five five-day sprints with labs available around the clock, allowing participants to manage their own priorities and time.

48 hours

Performance examination

A two-day examination validates execution, analysis, reporting and decision-making after the program.

Online

Independent, continuously evaluated

Mentors and the AI-supported evaluation engine review work; there is no conventional instructor-led course flow.

Enrollment process

  1. 01

    Application and payment

    Complete the application form to receive the payment link and available starting-date information by email.

  2. 02

    Start-date selection

    Select the start date before beginning the journey. The certification is designed to start at the beginning of each month.

  3. 03

    Certification program

    Receive access details for the simulation environment together with guidance on the program and its next steps.

  4. 04

    Examination

    Complete a 48-hour performance-based examination after the 25-day, five-sprint program.

07 / FAQ

Before you apply

What the simulation demands.

Do you offer a student discount?

Yes. Candidates with a verifiable academic email address can claim a 20% student discount.

Will I be required to write reports?

Yes—extensively, both during the program and the examination. Reporting is treated as an operational product, so participants prepare reports, briefs and notes for most activities.

Is the program online?

Yes. Aegis is fully online. The S46 Simulation environment manages tasks, labs, incidents, vigilance practices and threat-hunting reports.

Is a prerequisite course or certification required?

No prior course or certification is required. Aegis is the first program in the Aegis, Alpha and Ranger pathway.

What technical foundations are required?

Candidates should understand basic scripting, networking and common services, SIEM and logging concepts, and fundamental Linux and Windows administration. Existing experience with QRadar or another SIEM is beneficial.

Is the program instructor-led?

No. Aegis is self-directed and performance-based. Mentors and an AI-supported profiling engine review submissions and add feedback when required.

Are conventional course materials provided?

No conventional course pack is used. S46 assigns work as it would be assigned in a company, and participants can use appropriate independent resources to complete tasks on time.

How long does the program last?

The program lasts 25 days across five five-day sprints. Labs remain available around the clock. A two-day, 48-hour examination follows the program.

Can I continue working during the program?

Yes, although Aegis is deliberately intensive. Success requires disciplined prioritization, decision-making and time management alongside your existing responsibilities.

How many examination attempts are included?

One examination attempt is included. Additional attempts can be purchased if required.

Ready to enter the simulation?

Find the signal under pressure.

Talk to Cyber Struggle