Description
SEC555: Detection Engineering and SIEM Analytics. This course is a hands-on training that provides the skills necessary to identify and respond to cyber threats. This course teaches participants how to design proactive detection strategies and effectively manage SIEM platforms. Through real-world scenario-based labs, participants learn to interpret log data, create high-quality detection rules, and uncover hidden threats in on-premises and cloud environments. This course is designed for security analysts and engineers who aim to gain practical expertise in investigating attacks and improving reporting strategies. The course content aligns directly with the GCDA certification and validates advanced capabilities in data-driven detection and defense engineering. Ultimately, this course helps professionals build a responsive, cyber-intelligence-driven security operations center and extract meaningful insights from complex data.
What you will learn
- Build and configure your own threat discovery lab environment.
- Writing discovery rules to identify enemy behaviors.
- Optimize SIEM architecture for better performance and visibility.
- Conducting simulations of enemy attacks and analyzing related activities for reporting.
- Evaluate security controls using real log data.
- Manage and filter large volumes of data from various sources.
- Gain expertise in SIEM tools (on-premises and cloud), MITRE ATT&CK mapping, SOAR integration, and discovery tracking.
- Understand critical business concepts: Identify and mitigate threats in real time, prioritize threats based on asset importance, and improve alert accuracy to reduce fatigue and increase team efficiency.
This course is suitable for people who:
- Threat Detection Engineer
- Threat Detection Analyst
- Security Analyst
- Security Engineer
- Threat Hunter
- Incident Handler/Responder
- Security Architect
- Security Monitoring Specialist
- Cyber Threat Investigator
- Penetration Tester
Course Description SEC555: Detection Engineering and SIEM Analytics
- Publisher: SANS
- Instructor: Nick Mitropoulos
- Training level: Beginner to advanced
- Training duration: 48 hours and 4 minutes
- Number of lessons: 6
Course headings

Course Prerequisites SEC555: Detection Engineering and SIEM Analytics
- A basic understanding of:
- TCP/IP
Logging methods and techniques
Overall operating system fundamentals
Nice-to-haves: - Logging systems experience (both network and host)
Command-line activity familiarization
Detection engineering and/or SIEM tool exposure
Course images
Sample course video
Installation Guide
After Extract, view with your favorite player.
Subtitles: None
Quality: 720p
PDF file download link
USB file download link
Video file download link
File(s) password: www.downloadly.ir
File size
188 MB, 19.8 GB, 1.8 GB
