Skip to main content
← All training programs
AdvancedHands-on labs

Instructor-led training · Hands-on practice

Security Engineering L3

Build and test security detections in Splunk, Microsoft Defender, and AWS through guided attack simulations.

Course at a glance

Learn to build, test, and improve security detections.

LevelAdvanced
Duration35 Hours
FormatOnline — instructor-led with labs and recordings
7Modules
12Core tools
Live classes35 live sessions
RecordingsRecordings included
Trainer supportTrainer support included
AssessmentAssessment and certificate included
Weekly commitment6 hours per week
Program overview

Build and test the detections security teams rely on.

This advanced, seven-module course focuses on Splunk operations, detection design and testing, Microsoft Defender investigations, AWS security, and security automation. Guided labs and attack simulations let you practise the work of a security engineer.

Core focus

Advanced SplunkDetection EngineeringMicrosoft DefenderAWS Cloud SecurityThreat HuntingSOAR & Automation
Course fit

Is this training right for you?

Check the background expected before you explore the full curriculum.

Who it’s for

  • Security Engineers
  • SOC L2/L3 Analysts
  • Detection Engineers
  • Cloud Security Engineers
  • Incident Responders

What you should know first

  • Working knowledge of SOC operations and incident investigation
  • Hands-on familiarity with SIEM searches, Windows telemetry, and networking
  • Prior exposure to Splunk, EDR, or cloud security is strongly recommended

How you’ll practise

  • Detection-engineering challenges
  • Threat-hunting challenges
  • Incident-response scenarios
  • SPL & KQL exercises
  • Capstone attack simulations
What you’ll learn

Skills you’ll practise in this course.

Each outcome is tied to practical investigation or engineering work.

  • Design and operate a multi-source Splunk security lab
  • Onboard and normalize diverse log sources using CIM and data models
  • Engineer high-fidelity, ATT&CK-mapped detections and correlation rules
  • Write and tune Sigma rules and convert them to Splunk
  • Hunt across Microsoft Defender for Endpoint using advanced KQL
  • Investigate IAM, CloudTrail, GuardDuty, and EC2 security events in AWS
  • Run enterprise incident-response and structured threat-hunting workflows
  • Automate enrichment and response with SOAR and Python
Tools and methods

Tools you’ll work with.

See the platforms and methods used throughout the lessons and labs.

Splunk Enterprise
SIEM
Sysmon
Endpoint Telemetry
Microsoft Defender for Endpoint
EDR/XDR
Amazon Web Services
Cloud
AWS GuardDuty
Cloud Threat Detection
AWS CloudTrail
Cloud Logging
MITRE ATT&CK
Detection Framework
Sigma
Detection Rules
Search Processing Language
SPL
Kusto Query Language
KQL
Python
Security Automation
JSON
Data Format
Your work

What you’ll produce.

Build practical work you can discuss and explain, not just a record of attendance.

  • CIM-normalized Splunk data model and security dashboard
  • ATT&CK-mapped SPL correlation searches
  • Sigma rule with conversion and tuning notes
  • KQL threat-hunting query pack
  • AWS incident-investigation report
  • Automated IOC-enrichment workflow
  • Capstone detection and response report

Assessment standards

Completion is based on applied work, not attendance alone.

  • Telemetry selection and normalization quality
  • Detection logic, documentation, validation, and tuning rationale
  • Threat-hunting methodology and evidence handling
  • Incident scope, response decisions, and technical accuracy
  • Quality of the capstone report and engineering recommendations

Safe lab conduct

Exercises remain inside authorized, isolated training environments.

  • Use only authorized training accounts, systems, and simulation data
  • Keep credentials, tokens, and investigation evidence out of source files and reports
  • Validate detections in the lab before enabling automated response actions
  • Document changes and restore or clean up lab resources after each exercise
Curriculum

Explore the 7 course modules.

Open a module to see its topics and hands-on exercises.

Splunk Enterprise Architecture

  • Indexers
  • Search Heads
  • Heavy Forwarders
  • Universal Forwarders
  • Parsing pipelines
  • Indexing pipelines

Security Dashboards & Use Cases

  • Authentication monitoring
  • Privilege-escalation monitoring
  • Endpoint monitoring
  • Threat-activity dashboards
  • Executive security dashboards
  • Threat-hunting dashboards

Advanced Log Onboarding

  • Windows Event Logs
  • Sysmon integration
  • Linux logs
  • AWS CloudTrail
  • AWS VPC Flow Logs
  • Custom log parsing & sourcetypes
  • Index design strategy
  • Field extractions
  • props.conf & transforms.conf
  • CIM normalization & data models

Advanced SPL & Performance

  • stats, eventstats, streamstats
  • transaction, rex, regex, eval
  • lookup, join, append, mvexpand
  • bin, chart, timechart, tstats
  • Accelerated data models
  • Query optimization & summary indexing
  • Search acceleration & data retention

Module labs

Onboard Sysmon logsParse custom logsBuild dashboardsNormalize logs using CIMInvestigate attack activityCreate SPL detections

Practical labs

Put the lessons into practice.

Use lab evidence and security tools to work through investigation and response decisions.

Lab environment

A practical stack designed to keep learner infrastructure accessible, including AWS Free Tier where applicable.

  • Splunk Enterprise Server
  • Windows 11 VM
  • Windows Server VM
  • Kali Linux VM
  • AWS Free Tier account
  • Microsoft Defender trial environment
  • Sysmon-enabled endpoints
Learning path

Part of the Security Engineer path.

Progress from SOC foundations into advanced Splunk, detection engineering, endpoint and cloud security, and automation — the full security-engineering stack.

SOC FoundationsAdvanced SplunkDetection EngineeringMicrosoft DefenderCloud SecurityThreat HuntingSecurity AutomationCapstone
Explore full interactive roadmap →

Mentorship & guidance

Need help with a topic or your next career step?

Use mentorship to work through difficult concepts, plan what to study next, and prepare for interviews.

Enquire about mentorship

Next step

Is Security Engineering L3 right for you?

Ask about the next cohort, course schedule, and whether your experience is a good fit.