Skip to main content
← All training programs
Intermediate to AdvancedApplied exercises

Practical training · Course outline

Detection Engineering

Build, test, and tune detections across identity, endpoint, network, and cloud logs.

Course at a glance

Turn security logs into detections your team can explain, test, and trust.

LevelIntermediate to Advanced
Duration35 Hours
FormatSchedule and format confirmed on enquiry
8Modules
6Tools & methods

This is the course outline. Ask us about the next cohort, delivery format, and which training platforms will be available before enrolling.

Program overview

Build and test the detections security teams rely on.

A focused 35-hour course for analysts ready to move from investigating alerts to building them. Learn to choose the right log sources, write clear detection logic, test it against suspicious and benign examples, and document when a rule should fire. Finish by bringing the workflow together in a reviewable detection pack.

Core focus

Detection lifecycleIdentity and endpoint signalsNetwork and cloud telemetrySPL and KQL logicValidation and tuningHuman-approved automation
Course fit

Is this training right for you?

Check the background expected before you explore the full curriculum.

Who it’s for

  • SOC analysts moving into detection engineering
  • Junior detection engineers
  • Incident responders who want to build better alerts

What you should know first

  • Comfortable investigating common SOC alerts
  • Basic understanding of Windows and network logs
  • Introductory experience searching in a SIEM

How you’ll practise

  • Work through focused detection-design scenarios
  • Explain why an alert fired and when it should not
  • Review and improve a final detection pack
What you’ll learn

Skills you’ll practise in this course.

Each outcome is tied to practical investigation or engineering work.

  • Identify the telemetry a detection needs before writing a query
  • Write and explain SPL or KQL logic against the data available to you
  • Map a rule to the attacker behavior it is meant to detect
  • Test a rule with malicious and benign examples, then reduce noise
  • Document alert context and a sensible investigation path
  • Present a detection pack with assumptions, test cases, and gaps
Tools and methods

Platforms and methods in the syllabus.

Hands-on access to a platform depends on the cohort. Confirm the available environment before enrolling.

MITRE ATT&CK
Threat model
Splunk & SPL
SIEM search
Kusto Query Language
Query language
Sigma
Rule format
Windows & Sysmon logs
Endpoint telemetry
Cloud audit logs
Cloud telemetry
Your work

What you’ll produce.

Build practical work you can discuss and explain, not just a record of attendance.

  • Detection hypotheses and data-source notes
  • ATT&CK-mapped rule drafts
  • Positive and benign test cases
  • Tuning decisions and responder guidance
  • Capstone detection pack

Assessment standards

The capstone is designed to test your reasoning and rule quality.

  • The rule describes a specific observable behavior
  • Required fields and data-source assumptions are documented
  • Tests include suspicious and benign examples
  • Tuning choices preserve useful coverage
  • The response guidance is supported by the evidence

Safe lab conduct

Exercises use sample or explicitly authorized training data.

  • Use sample or explicitly authorized training data only
  • Never run containment against a real device as part of an exercise
  • Treat AI suggestions as drafts that require human validation
  • Record assumptions and evidence for every conclusion
Curriculum

Explore the 8 course modules.

Open a module to see its key topics and proposed practice exercise.

  • What a detection should explain: behavior, data, logic, and response
  • Map attacker behavior to MITRE ATT&CK without treating every technique as a rule
  • Select useful fields and normalize records across log sources
  • Read basic SPL and KQL searches; document data assumptions

Module exercises

Map sample authentication events to a detection hypothesis

Practice scenarios

Put the lessons into practice.

These are the exercises planned in the course outline. Platform access is confirmed before enrolment.

Course exercises

  • Password-spray detection using sample sign-in events
  • Suspicious process-chain investigation
  • Network beaconing and DNS review
  • Cloud privilege-change rule exercise
  • Approval-gated response workflow design
  • Final detection pack with test cases and tuning notes
Learning path

Part of the Detection Engineer path.

Specialize in the detection lifecycle: from ATT&CK-driven strategy through SPL and Sigma authoring, correlation rules, tuning, and validation.

SOC FoundationsAdvanced Log AnalysisSplunk & SPLMITRE ATT&CKDetection EngineeringSigmaCorrelation RulesDetection TuningDetection ValidationCapstone Challenge
Explore full interactive roadmap →

Mentorship & guidance

Need help with a topic or your next career step?

Use mentorship to work through difficult concepts, plan what to study next, and prepare for interviews.

Enquire about mentorship

Next step

Is Detection Engineering right for you?

Ask about the next cohort, course schedule, and whether your experience is a good fit.