OSDA Exam Prep & Study Resources

OffSec certification · 2 products

SOC-200 | OffSec Defense Analyst

Study materials for OSDA

Frequently asked questions

What is OSDA?

OSDA (OffSec Defense Analyst) is OffSec's blue team certification, based on the SOC-200 course. Unlike OffSec's offensive certifications, OSDA is designed for defensive security professionals, specifically SOC analysts and incident responders. It teaches candidates how to detect, triage, and investigate attacks by analyzing logs, using SIEM tools, and applying threat hunting techniques. OSDA gives defenders insight into real attacker tactics, techniques, and procedures (TTPs) by teaching detection from the perspective of someone who understands how those attacks are actually executed.

Who should take OSDA?

OSDA is designed for SOC analysts (Tier 1 and Tier 2), incident responders, threat hunters, and blue team professionals who want a structured, practical certification validating their detection and investigation skills. It is also valuable for red teamers who want to understand what defenders see when attacks occur, improving their ability to operate stealthily. Professionals who work in security operations centers, manage SIEM platforms, or respond to alerts on a daily basis will find the most direct career benefit from earning OSDA.

How hard is OSDA?

OSDA is moderately challenging and generally considered more accessible than OffSec's offensive certifications like OSCP. However, it is not trivial. The exam requires candidates to analyze logs and network captures under time pressure, identify attacker actions across multiple systems, and reconstruct a complete attack chain from evidence alone. Candidates who have not worked with log analysis or SIEM platforms before may find it more demanding. Completing the SOC-200 course labs thoroughly and gaining hands-on experience with a SIEM platform before the exam significantly improves pass rates.

What topics does OSDA cover?

OSDA covers the core skills required for effective security operations center work. Topics include SIEM fundamentals and query writing, Windows Event Log analysis, Linux syslog analysis, network traffic and packet capture analysis, detecting common attacker TTPs such as privilege escalation, lateral movement, credential theft, and data exfiltration, threat hunting methodologies, and structured incident investigation workflows. The SOC-200 course is designed to teach these skills through realistic attack scenarios rather than purely theoretical content.

Prerequisites for OSDA?

There are no formal prerequisites for OSDA, but candidates should have a basic understanding of TCP/IP networking, Windows and Linux operating systems, and common log formats including Windows Event Logs and syslog. Familiarity with at least one SIEM platform such as Splunk, Elastic SIEM, or Microsoft Sentinel is helpful but not required, the course teaches the necessary platform skills. A general awareness of common attack techniques and the cyber kill chain will also help candidates contextualize the detection scenarios covered in the SOC-200 material.

Is OSDA worth it for SOC analysts?

Yes. OSDA is one of the few hands-on blue team certifications backed by OffSec's strong reputation in the security community. Most defensive certifications on the market are knowledge-based multiple-choice exams, making OSDA stand out as a practical, evidence-based credential. It validates real-world detection and investigation skills that are directly applicable in day-to-day SOC work. For SOC analysts looking to advance their careers, differentiate themselves from candidates with only knowledge-based credentials, or transition into threat hunting and incident response roles, OSDA is a valuable investment.

What is the OSDA exam format?

The OSDA exam is a timed practical assessment where candidates analyze logs, network packet captures, and other forensic artifacts collected from a simulated attack scenario. You must investigate the attack, identify the attacker's actions step by step, and answer specific questions about the attack chain, tools used, lateral movement paths, and exfiltration methods. The exam format closely resembles a real incident investigation, testing whether candidates can reconstruct what happened from evidence rather than just recognizing attack names from a multiple-choice list.

Related

All OffSec certifications · Browse cheatsheets