A hands-on mid-level course that builds detections which catch real attacks without drowning the SOC in noise. Work the detection pipeline - eight stages from idea to measured value: Sources, Hypothesis, Author, Test, Tune, Deploy, Coverage, and Measure - writing threat-informed, robust, tested, tuned, and measured detections with real Sigma rules, SIEM queries, safe atomic tests, and ATT&CK coverage. Four hands-on activities in every lesson.
Sign in to enrol — you can pay by bKash or Nagad, or apply a promo code.