Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Security Engineering: Threat Detection and Monitoring

This security engineering course in Toronto is about the system behind the alerts. Over eight weeks you design continuous monitoring for an environment you do not fully control, then build adversary informed detection use cases from log, endpoint and network telemetry.

The starting position is that architecture and detection are the same problem. A defensible design decides what you can see, and what you can see decides what you can catch.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
Security Essentials: Network, Endpoint and Cloud
Class size
Capped at 12 learners
Security Engineering: Threat Detection and Monitoring

What you will be able to do

  • Design a telemetry collection plan that fits a real budget
  • Write detection use cases derived from specific attacker techniques
  • Instrument Windows, Linux and cloud workloads for meaningful visibility
  • Assess an existing architecture and name its monitoring blind spots
  • Build detections that keep working after the environment changes
  • Measure detection coverage and report it honestly to leadership
  • Set data retention and cost boundaries you can defend in a budget meeting

Course outline

6 modules

  • Designing for visibility rather than adding it later
  • Trust zones, chokepoints and enforcement points
  • Identity as the primary control plane
  • Where legacy systems force compromises
  • Documenting an architecture others can operate

What you need before you start

  • Security Essentials or comparable operational security experience
  • Practical familiarity with at least one operating system in production
  • Basic scripting or query writing ability in any language
  • Willingness to design under real constraints rather than ideal ones

Who this course is for

  • Security engineers building or rebuilding a monitoring capability
  • SOC analysts moving into engineering work
  • Infrastructure and platform engineers taking on detection duties
  • Team leads deciding what telemetry to fund
  • Consultants assessing client monitoring maturity

Where this leads

Prepares you for

CySA+

Awarded by CompTIA

The monitoring and detection content maps well to CompTIA CySA+. CompTIA, not the academy, examines candidates and issues the credential. The included study notes are supplementary; the course is built around engineering practice first.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.