Detection Engineering and SIEM Analytics
This security information and event management (SIEM) training in Canada is for engineers who write the rules rather than work the queue. Ten weeks on detection engineering as a discipline: hypothesis, data, logic, testing, deployment and the tuning that follows.
SIEM platforms rarely fail because of the tool. They fail because rules were written against clean lab data, never tested against production noise, and never maintained after the person who wrote them left.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- SOC Analyst Training Program
- Class size
- Capped at 12 learners

What you will be able to do
- Convert an attacker technique into a written detection specification
- Write analytics that survive contact with production noise
- Test a detection against both emulated attacks and normal activity
- Version, review and deploy detections through a pipeline
- Measure and control the false positive rate of a rule set
- Retire or rewrite detections when the environment changes underneath them
- Report detection coverage against MITRE ATT&CK without inflating it
- Investigate why a detection that should have fired did not
Course outline
6 modules
- Why alert counts are the wrong measure
- The detection lifecycle from idea to retirement
- Working from a repository rather than a console
- Roles: engineer, analyst and hunter
- Setting a false positive budget with the SOC
What you need before you start
- SOC Analyst Training or about a year of hands-on SIEM investigation work
- Confidence writing queries in at least one search language
- Basic scripting and familiarity with version control
- Access to a machine that can hold a lab session for three hours
Who this course is for
- Detection engineers and senior SOC analysts
- Threat hunters formalizing findings into durable rules
- Security engineers who own a SIEM platform
- Purple team members translating attacks into detections
- Managed detection providers standardizing content across clients
Where this leads
Prepares you for
CySA+
Awarded by CompTIA
The analytics and monitoring material overlaps with CompTIA CySA+. That credential is examined and awarded by CompTIA; nothing here is issued by the academy. Detection engineering itself has no vendor neutral certification, so the portfolio you build matters more.
Questions about this course
More in cyber defence
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



