Five operational sprints
Five five-day sprints with labs available around the clock, allowing participants to manage their own priorities and time.
Certifications / Aegis
Adaptive, experiential skill acquisition for SOC analysts—inside a living operation shaped by incidents, deadlines and uncertainty.
A realistic CSOC simulation
Aegis is a dynamic online program built for SOC analysts. For 25 days, participants work inside a realistic corporate network and confront tasks that reflect operational life.
The Scrum framework makes time management, prioritization and decision-making part of the assessment. Random incidents test readiness and resilience by introducing the pressure, ambiguity and interruptions that define real cybersecurity operations.
The certification is the first step in the Aegis, Alpha and Ranger pathway. It establishes an interdisciplinary baseline for SOC analysts and threat hunters by connecting defensive investigation, offensive context and strategic thinking.
I highly recommend the Aegis Certification because it prepares analysts for one of the SOC’s greatest challenges: working miracles in limited time and under intense pressure. The content was strong, the labs were engaging and the examination was challenging. Candidates need dedication, focus, motivation and a willingness to leave their comfort zone.
Three connected dimensions
Aegis connects monitoring and incident handling with offensive experimentation and the human skills required to operate under pressure.
Security monitoring, threat detection and incident handling continue around the clock inside a living CSOC environment. Participants work with SIEM platforms such as IBM QRadar, ELK and Splunk rather than isolated capture-the-flag exercises.
Linux and Windows systems form an Active Directory environment where participants conduct attacks, observe their own activity in the logs, and use the evidence to test and improve SIEM rules.
A corporate storyline, task management, backlogs, daily stand-ups, retrospectives and five-day sprints develop prioritization, communication, decision-making and resilience under pressure.
We appreciate technology, but we believe in peopleWe appreciate technology, but we believe in people
Eight operating principles
The program replaces passive instruction with work that must be prioritized, delivered, evaluated and improved inside a changing environment.
Work inside a small, living environment that includes SIEM, EDR, Active Directory and other SOC capabilities instead of completing disconnected exercises.
Manage exercises, assignments and submissions through a task system. Every sprint begins with work that must be evaluated, prioritized and delivered.
Random incidents develop mental resilience, incident focus, reactive capability and the determination to continue when conditions change unexpectedly.
Run your own Scrum process, organize backlogs around weekly tasks and due dates, and strengthen project-management and decision-making skills.
Develop use cases, write rules and build correlations while responding to incidents in a dynamic environment shaped by pressure and uncertainty.
Replace passive course material with real tasks, independent research and accountable execution. Mistakes become evidence for reflection and growth.
Intensive scenarios reinforce prioritization, planning, extreme ownership, persistence and the ability to learn while operating through failure.
Mentors and an AI-supported engine evaluate task submissions and provide comments whenever additional feedback is needed.

A living analyst workflow
A participant’s day resembles that of an analyst in a heavily targeted security operations center. Periodic transitions between routine work and unexpected incidents develop adaptability, pressure-tested judgment, planning and resilience.
Evaluate the previous day, record challenges, decisions, feelings and solutions, then plan the work ahead.
Review assigned work and due dates, then make deliberate decisions about priority, effort and timing.
Hunt unknown threats, analyze malware, tune SIEM rules, create correlations, investigate false positives and review indicators of compromise.
When the command-and-control engine launches an internal, external or APT-style incident, stop routine work and focus on root cause, impact and incident management.
Enabled by S46
S46 Simulation Software manages the full certification process. After enrollment, participants receive their account, guides and instructions for accessing the operational environment.


Aegis holders can
Foundations and commitment
Candidates need basic scripting, networking and common-service knowledge, familiarity with SIEM and logging concepts, and fundamental Linux and Windows skills. Motivation, dedication and discipline are equally important.
Five five-day sprints with labs available around the clock, allowing participants to manage their own priorities and time.
A two-day examination validates execution, analysis, reporting and decision-making after the program.
Mentors and the AI-supported evaluation engine review work; there is no conventional instructor-led course flow.
Enrollment process
Complete the application form to receive the payment link and available starting-date information by email.
Select the start date before beginning the journey. The certification is designed to start at the beginning of each month.
Receive access details for the simulation environment together with guidance on the program and its next steps.
Complete a 48-hour performance-based examination after the 25-day, five-sprint program.
Before you apply
Yes. Candidates with a verifiable academic email address can claim a 20% student discount.
Yes—extensively, both during the program and the examination. Reporting is treated as an operational product, so participants prepare reports, briefs and notes for most activities.
Yes. Aegis is fully online. The S46 Simulation environment manages tasks, labs, incidents, vigilance practices and threat-hunting reports.
No prior course or certification is required. Aegis is the first program in the Aegis, Alpha and Ranger pathway.
Candidates should understand basic scripting, networking and common services, SIEM and logging concepts, and fundamental Linux and Windows administration. Existing experience with QRadar or another SIEM is beneficial.
No. Aegis is self-directed and performance-based. Mentors and an AI-supported profiling engine review submissions and add feedback when required.
No conventional course pack is used. S46 assigns work as it would be assigned in a company, and participants can use appropriate independent resources to complete tasks on time.
The program lasts 25 days across five five-day sprints. Labs remain available around the clock. A two-day, 48-hour examination follows the program.
Yes, although Aegis is deliberately intensive. Success requires disciplined prioritization, decision-making and time management alongside your existing responsibilities.
One examination attempt is included. Additional attempts can be purchased if required.
Ready to enter the simulation?