Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

Detection Engineering and SIEM Analytics

This security information and event management (SIEM) training in Canada is for engineers who write the rules rather than work the queue. Ten weeks on detection engineering as a discipline: hypothesis, data, logic, testing, deployment and the tuning that follows.

SIEM platforms rarely fail because of the tool. They fail because rules were written against clean lab data, never tested against production noise, and never maintained after the person who wrote them left.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
SOC Analyst Training Program
Class size
Capped at 12 learners
Detection Engineering and SIEM Analytics

What you will be able to do

  • Convert an attacker technique into a written detection specification
  • Write analytics that survive contact with production noise
  • Test a detection against both emulated attacks and normal activity
  • Version, review and deploy detections through a pipeline
  • Measure and control the false positive rate of a rule set
  • Retire or rewrite detections when the environment changes underneath them
  • Report detection coverage against MITRE ATT&CK without inflating it
  • Investigate why a detection that should have fired did not

Course outline

6 modules

  • Why alert counts are the wrong measure
  • The detection lifecycle from idea to retirement
  • Working from a repository rather than a console
  • Roles: engineer, analyst and hunter
  • Setting a false positive budget with the SOC

What you need before you start

  • SOC Analyst Training or about a year of hands-on SIEM investigation work
  • Confidence writing queries in at least one search language
  • Basic scripting and familiarity with version control
  • Access to a machine that can hold a lab session for three hours

Who this course is for

  • Detection engineers and senior SOC analysts
  • Threat hunters formalizing findings into durable rules
  • Security engineers who own a SIEM platform
  • Purple team members translating attacks into detections
  • Managed detection providers standardizing content across clients

Where this leads

Prepares you for

CySA+

Awarded by CompTIA

The analytics and monitoring material overlaps with CompTIA CySA+. That credential is examined and awarded by CompTIA; nothing here is issued by the academy. Detection engineering itself has no vendor neutral certification, so the portfolio you build matters more.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.