Official IBM course · SQR01 · SOC analyst level

IBM QRadar SIEM 7.6
Cybersecurity analyst

Course SQR01: four days of real investigation on QRadar SIEM 7.6. Correlation, offence tuning, AQL over Ariel, integration with IBM X-Force and executive reporting. First course in SIXE's series for SIEM analysts.

Duration4 intensive days
FormatOnsite or live online
LanguagesEN · ES · FR
Course codeSQR01 · Level 1
[ 01 ]Why this course

Train SOC analysts who actually investigate with QRadar.

In many teams QRadar ends up used as an alert dashboard: offence arrives, offence gets closed, next ticket. This course teaches how to get real value from the platform: understand the architecture, model networks and assets, write rules that matter, and use offences as a starting point for genuine investigation.

The programme covers QRadar SIEM 7.6 end to end from the analyst's viewpoint: AQL queries against Ariel, integration with IBM X-Force, real-world cases (banking fraud, C2 traffic, port scans, dormant accounts, WannaCry, anomalous user behaviour) and executive reporting for management and ISO 27001 audit.

By the end, the student handles the platform as an analyst — not as a ticket operator.

[ 02 ]Programme · at a glance

Areas covered by the SQR01 course

Five blocks that group the 6 official modules of the programme. Each block ends with guided lab work on a real QRadar 7.6 environment.

  1. 01

    QRadar architecture and deployment

    Components, internal data flow, log source integration, troubleshooting and a full simulation of the student's environment for the rest of the course.

  2. 02

    Networks and assets

    Internal and external network discovery, domains, multi-tenancy setups, automatic asset detection and perimeter modelling — the base QRadar needs to correlate well.

  3. 03

    Attack investigation

    Rules engine and building blocks, efficient searches, tuning and offence management, use of reference sets, AQL queries against Ariel, and integration with IBM X-Force Threat Intelligence.

  4. 04

    Real-world use cases

    Banking fraud, C2 traffic, port scans, dormant accounts, risky actions, data protection, physical access control, WannaCry and anomalous user behaviour detection.

  5. 05

    Compliance and open lab

    Regulatory compliance (ISO 27001 and similar), executive reporting, access for non-technical roles, and a final open session on the student's own environment.

The full syllabus — modules, subtopics and lab scripts — is sent with the commercial proposal. Course based on the official 7.6 release of QRadar SIEM.

[ 03 ]By the end

What your team takes away

After four days on a real QRadar SIEM 7.6, the student can do these four things:

Investigation Investigate offences with judgement Read the offence, follow the trail with searches and AQL, and rule out false positives without closing by reflex.
Detection Tune rules and use cases Adjust the CRE, write custom rules, manage reference sets and raise the signal-to-noise ratio of your alerts.
Intelligence Query IBM X-Force Enrich investigations with threat feeds from IBM X-Force straight from QRadar.
Reporting Reports for management and audit Dashboards and executive reports for the leadership team, ISO 27001 auditors and non-technical stakeholders.
[ 04 ]Who it's for

Technical roles with SOC responsibility

SOC

SOC analysts L1 and L2

Already handling alerts and looking to master QRadar from the inside.

Cybersecurity

Cybersecurity technicians

Joining the security team and stepping into SIEM operations.

Systems

Sysadmins moving to security

Systems or network profiles specialising in detection and monitoring.

Public sector

Government and defence

Organisations with QRadar deployed that need to train in-house analysts.

[ 05 ]Why with us

Courses built around what your team actually does

  1. 01IBM Business PartnerWe are an official IBM training partner in security. See also our full IBM official training catalogue.
  2. 02On the current release (7.6)All material and labs are reviewed against QRadar SIEM 7.6. No stale screenshots, no menus that no longer exist.
  3. 03Instructors with real experienceTrainers who have deployed and run QRadar in banking, telco and public administration, not just in a lab.
  4. 04Lab on a real instanceEach block closes by investigating offences on a real QRadar 7.6: fraud, C2, port scans, WannaCry and more.
  5. 05Adapted to the rolePace and depth adjusted to the profile: SOC analyst L1/L2, cybersecurity technician or sysadmin moving into security.
  6. 06Open final sessionDay four closes with questions from the student's real environment: custom rules, integrations and specific tuning.
  7. 07EN · ES · FR · from 2 studentsOnsite or live remote in three languages, with in-company delivery available.

Custom training for your SOC?

Tell us where the team stands, which use cases you're prioritising and what integrations you already have. We adapt syllabus and pace. No commitment.

Contact us
[ 07 ]Frequently asked

Frequently asked questions

What prior knowledge do I need for SQR01?

General TCP/IP networking, familiarity with system logs and basic cybersecurity concepts. No prior QRadar or SIEM experience required. If the student is starting truly from scratch, it's useful to take SIEM Fundamentals beforehand.

Which QRadar version is used?

IBM QRadar SIEM 7.6, the current stable release. We update syllabus, screenshots and lab scripts with every relevant release.

Is this a QRadar administration course?

No. SQR01 is the cybersecurity analyst course: it focuses on investigation, correlation and reporting. Installation, log source integration and platform operation are covered in Deployment and administration.

Is this official IBM training?

Yes. SIXE is an IBM Business Partner in security training and works with official IBM materials and course codes. See our full IBM training catalogue.

Can I take SQR01 online?

Yes. Onsite or live remote with an instructor. The QRadar 7.6 lab environment is the same in both modes.

Do you deliver in-company training?

Yes. On the client's premises or remotely for the whole team, adapting schedule, use cases and content to the company's real environment.

Does the course cover ISO 27001 compliance?

Yes, within the compliance block: how to generate the reports and evidence that ISO 27001 and similar audits require, using QRadar as the source. If you need a dedicated compliance course, let us know.

What integrations are set up in the lab?

The course environment ships with typical log sources (Windows, Linux, network, application), flows, discovered assets and IBM X-Force feeds. Use cases run on prepared data that simulates fraud, C2, scans and insider compromise.
[ 08 ]   Get started

Let's train your SOC as QRadar analysts

Tell us where the team stands, its size and preferred language. We send back a proposal with dates and pricing tailored to you — no generic catalogue.

Duration4 intensive days
CodeSQR01
LanguagesEN · ES · FR
GroupsFrom 2 students