Network Monitoring and Threat Detection
This threat detection course in Toronto is for analysts who work at packet level. Ten weeks on protocol behaviour, intrusion detection and prevention system (IDS and IPS) engineering, and hunting adversaries in network data before an alert ever fires.
You spend most of the time in capture files and sensor configuration rather than slides. The assumption is that you already triage alerts and now need to explain why the sensor saw what it saw.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- SOC Analyst Training Program
- Class size
- Capped at 12 learners

What you will be able to do
- Read a capture file at protocol level without relying on tool summaries
- Write and tune Suricata rules that fire on behaviour rather than strings
- Place sensors so coverage matches the traffic that actually matters
- Detect command and control in encrypted traffic using metadata alone
- Run a structured network hunt from hypothesis to conclusion
- Measure detection coverage against MITRE ATT&CK and name the gaps
- Distinguish a misconfigured application from an attacker doing the same thing
- Justify sensor and retention spending to a budget holder
Course outline
6 modules
- TCP state, retransmission and what breaks it
- DNS as an attacker channel and a detection surface
- HTTP, TLS and the metadata that survives encryption
- SMB, RDP and internal protocol abuse
- Reading unfamiliar protocols from first principles
What you need before you start
- SOC Analyst Training or equivalent alert queue experience
- Solid TCP/IP knowledge and comfort with Wireshark
- Command line competence on Linux
- A connection that can sustain lab sessions with large capture files
Who this course is for
- Intrusion analysts and network detection engineers
- SOC analysts specializing in network telemetry
- Threat hunters building a network practice
- Network engineers moving into security monitoring
- Incident responders who need packet level evidence
Where this leads
Prepares you for
CySA+
Awarded by CompTIA
The detection and monitoring material maps to CompTIA CySA+. CompTIA is the awarding body for that credential; this academy is not an examining organization. You book the exam directly and can use the revision notes included here.
Questions about this course
More in cyber defence
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



