Skip to content

SANS – SEC555: Detection Engineering and SIEM Analytics 2021-6

Updated August 10, 2026
SANS – SEC555: Detection Engineering and SIEM Analytics 2021-6

Download

About this item

Description

SEC555: Detection Engineering and SIEM Analytics. This course is a hands-on training that provides the skills necessary to identify and respond to cyber threats. This course teaches participants how to design proactive detection strategies and effectively manage SIEM platforms. Through real-world scenario-based labs, participants learn to interpret log data, create high-quality detection rules, and uncover hidden threats in on-premises and cloud environments. This course is designed for security analysts and engineers who aim to gain practical expertise in investigating attacks and improving reporting strategies. The course content aligns directly with the GCDA certification and validates advanced capabilities in data-driven detection and defense engineering. Ultimately, this course helps professionals build a responsive, cyber-intelligence-driven security operations center and extract meaningful insights from complex data.

What you will learn

  • Build and configure your own threat discovery lab environment.
  • Writing discovery rules to identify enemy behaviors.
  • Optimize SIEM architecture for better performance and visibility.
  • Conducting simulations of enemy attacks and analyzing related activities for reporting.
  • Evaluate security controls using real log data.
  • Manage and filter large volumes of data from various sources.
  • Gain expertise in SIEM tools (on-premises and cloud), MITRE ATT&CK mapping, SOAR integration, and discovery tracking.
  • Understand critical business concepts: Identify and mitigate threats in real time, prioritize threats based on asset importance, and improve alert accuracy to reduce fatigue and increase team efficiency.

This course is suitable for people who:

  • Threat Detection Engineer
  • Threat Detection Analyst
  • Security Analyst
  • Security Engineer
  • Threat Hunter
  • Incident Handler/Responder
  • Security Architect
  • Security Monitoring Specialist
  • Cyber ​​Threat Investigator
  • Penetration Tester