The OSDA (OffSec Defense Analyst) certification is a hands-on credential offered by Offensive Security, designed for professionals who want to build strong skills in defensive cybersecurity. It focuses on threat detection, security monitoring, and incident response, helping you understand how to identify and respond to real-world cyber threats.
Getting certified through OSDA training is a great step for individuals looking to start or advance their careers in cybersecurity, especially in security operations and blue team roles. The training emphasizes practical, real-world scenarios, enabling you to analyze attacks, monitor systems, and respond effectively to security incidents.

OSDA training is designed to be flexible for both beginners and working professionals. You can learn at your own pace, from anywhere with internet access, making it easy to balance your studies with work or other commitments.
OSDA training helps you build strong defensive cybersecurity skills, including threat detection, security monitoring, and incident response. This enables you to handle real-world security challenges and grow your career in high-demand blue team roles.
Everything you need to know about the curriculum and outcomes.

NYTCC’s OSDA training is designed to offer maximum flexibility, allowing you to learn at your own pace from anywhere. This makes it easy to balance your studies with work or other commitments.
What sets NYTCC apart is our team of experienced cybersecurity professionals who provide practical, hands-on training in defensive security, threat detection, and incident response. You’ll gain real-world experience through lab-based exercises and scenario-driven learning.
The course is comprehensive, covering everything you need to build strong blue team skills and succeed in the OSDA certification exam.
If you’re looking for OSDA training that is flexible, effective, and career-focused, NYTCC is the ideal choice.
| Exam Detail | Information |
|---|---|
| Associated Course | SOC-200 – Security Operations and Defensive Analysis |
| Certification | OffSec Defense Analyst (OSDA) |
| Main Objective | Detect, analyze, understand, and document attacker activity |
| Exam Type | Hands-on, proctored practical exam |
| Exam Environment | SIEM-based environment through a private VPN |
| Exam Duration | 23 hours 45 minutes |
| Report Submission Time | Additional 24 hours |
| Exam Structure | 10 phases |
| Points per Phase | Up to 10 points |
| Maximum Score | 100 points |
| Passing Score | 75/100 |
| Documentation | Professional technical report required |
| Proctoring | Yes |

The SOC-200: Security Operations and Defensive Analysis training for OSDA Certification starts at $1,749. The course focuses on practical defensive security, SOC operations, threat detection, incident analysis, and blue-team skills.
Knowledge weightage as per official certification standards.
| No. | Domain / Topic | Description |
|---|---|---|
| 1 | Attack Methodology Introduction | Build a foundation for understanding attacker behaviors and anticipating their actions during penetration testing engagements. |
| 2 | Windows Endpoint Introduction | Understand common Windows endpoint vulnerabilities and the attack vectors adversaries use against them. |
| 3 | Windows Server-Side Attacks | Learn techniques used to exploit critical services and vulnerabilities on compromised Windows servers. |
| 4 | Windows Client-Side Attacks | Analyze browser attacks, software vulnerabilities, and social engineering techniques targeting Windows users. |
| 5 | Windows Privilege Escalation | Explore misconfigurations and software vulnerabilities that attackers can use to increase system privileges. |
| 6 | Windows Persistence | Understand file system persistence, registry modifications, scheduled tasks, and other persistence techniques. |
| 7 | Linux Endpoint Introduction | Learn common attack vectors, security mechanisms, and vulnerabilities associated with Linux endpoints. |
| 8 | Linux Server-Side Attacks | Understand Linux server compromise through service exploits, configuration weaknesses, and privilege escalation. |
| 9 | Network Detections | Use firewalls, intrusion detection systems, and related technologies to identify malicious network activity. |
| 10 | Antivirus Alerts and Evasion | Understand antivirus detection and evasion methods, including payload obfuscation and exploit customization. |
| 11 | Network Evasion and Tunneling | Understand covert communications, network tunneling, lateral movement, and techniques used to evade defensive technologies. |
| 12 | Active Directory Enumeration | Gather information about Active Directory users, groups, permissions, and structure to identify potential attack paths. |
| 13 | Windows Lateral Movement | Analyze compromised credentials, remote execution, and network pivoting used for lateral movement in Windows environments. |
| 14 | Active Directory Persistence | Explore hidden accounts, service manipulation, and other methods attackers use to maintain access in Active Directory environments. |
| 15 | SIEM Part One | Build and configure an ELK SIEM using Elasticsearch, Logstash, and Kibana for security-log collection and analysis. |
| 16 | SIEM Part Two | Operationalize an ELK SIEM by collecting and normalizing logs, creating dashboards, and configuring security alerts. |
Professionals with OSDA certification can pursue roles such as Security Operations Center (SOC) Analyst, Cybersecurity Analyst, Incident Response Analyst, or Threat Detection Specialist. The demand for OSDA-certified professionals is increasing as organizations focus on strengthening their defensive security capabilities and protecting against evolving cyber threats.

The average salary for professionals who hold an OSDA certification ranges from $85,000 to $120,000 per year globally, depending heavily on the employer type, geographic location, and years of experience. [1]

OSDA (OffSec Defense Analyst) is a hands-on certification focused on defensive cybersecurity, including threat detection, monitoring, and incident response.
Beginners and professionals interested in blue team roles such as SOC analysts, cybersecurity analysts, and incident responders.
Fill out the form below and our team will get back to you shortly.
There are no strict prerequisites, but basic knowledge of networking, operating systems, and security fundamentals is helpful.
Training is flexible and self-paced. Most learners complete it within a few weeks depending on their schedule.
OSDA training can be taken online or in-person, offering flexibility for working professionals.
You will learn threat detection, security monitoring, log analysis, and incident response techniques.
Yes. The training is designed with practical exercises and real-world scenarios to prepare you for the certification exam.
Absolutely. OSDA certification opens opportunities in security operations and defensive cybersecurity roles with strong career growth potential.