Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

Network Monitoring and Threat Detection

This threat detection course in Toronto is for analysts who work at packet level. Ten weeks on protocol behaviour, intrusion detection and prevention system (IDS and IPS) engineering, and hunting adversaries in network data before an alert ever fires.

You spend most of the time in capture files and sensor configuration rather than slides. The assumption is that you already triage alerts and now need to explain why the sensor saw what it saw.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
SOC Analyst Training Program
Class size
Capped at 12 learners
Network Monitoring and Threat Detection

What you will be able to do

  • Read a capture file at protocol level without relying on tool summaries
  • Write and tune Suricata rules that fire on behaviour rather than strings
  • Place sensors so coverage matches the traffic that actually matters
  • Detect command and control in encrypted traffic using metadata alone
  • Run a structured network hunt from hypothesis to conclusion
  • Measure detection coverage against MITRE ATT&CK and name the gaps
  • Distinguish a misconfigured application from an attacker doing the same thing
  • Justify sensor and retention spending to a budget holder

Course outline

6 modules

  • TCP state, retransmission and what breaks it
  • DNS as an attacker channel and a detection surface
  • HTTP, TLS and the metadata that survives encryption
  • SMB, RDP and internal protocol abuse
  • Reading unfamiliar protocols from first principles

What you need before you start

  • SOC Analyst Training or equivalent alert queue experience
  • Solid TCP/IP knowledge and comfort with Wireshark
  • Command line competence on Linux
  • A connection that can sustain lab sessions with large capture files

Who this course is for

  • Intrusion analysts and network detection engineers
  • SOC analysts specializing in network telemetry
  • Threat hunters building a network practice
  • Network engineers moving into security monitoring
  • Incident responders who need packet level evidence

Where this leads

Prepares you for

CySA+

Awarded by CompTIA

The detection and monitoring material maps to CompTIA CySA+. CompTIA is the awarding body for that credential; this academy is not an examining organization. You book the exam directly and can use the revision notes included here.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.