Threat Detection Engineering
Master Threat Detection Engineering
Design, build, and operationalize advanced detection capabilities that actually stop modern threats across on-prem and cloud environments.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations
What Threat Detection Engineering teaches, the detection rules and pipeline you walk away with, the Microsoft detection surface you build against, and how the course is structured. Start here.
Show 11 lessonsHide lessons
- 0.1DE0.1 Detection Engineering. What It Is and Why It Is ImportantPreview
- 0.2DE0.2 Why Organizations Need Detection EngineersPreview
- 0.3DE0.3 The Detection Coverage, The Gap, The IllusionPreview
- 0.4DE0.4 The Microsoft Detection SurfacePreview
- 0.5DE0.5 Measuring DetectionPreview
- 0.6DE0.6 Walking CHAIN-HARVESTPreview
- 0.7DE0.7 The Six Attack Chains in DetailPreview
- 0.8DE0.8 MITRE ATT&CKPreview
- 0.9DE0.9 The Detection Engineering DisciplinePreview
- 0.10DE0.10 Tools and CapabilitiesPreview
- 0.11DE0.11 Creating a Detection Engineering BaselinePreview
How detection rules work architecturally in Sentinel and Defender XDR. The five-stage scheduled rule pipeline, entity mapping, alert enrichment, severity classification, ATT&CK coverage mapping, NRT rules, Defender XDR custom detections, alert grouping, incident architecture, and the rule specification template. You configure and deploy a production detection rule with every parameter set deliberately.
Show 9 lessonsHide lessons
- 1.1DE1.1 Sentinel Analytics Rule Types
- 1.2DE1.2 Anatomy of a Scheduled Rule
- 1.3DE1.3 Entity Mapping and Alert Enrichment
- 1.4DE1.4 Severity, MITRE Mapping, and Documentation
- 1.5DE1.5 NRT Rules and Defender XDR Custom Detections
- 1.6DE1.6 Alert Grouping and Incident Architecture
- 1.7DE1.7 The Rule Specification Template and Common Mistakes
- 1.8Module Summary
- 1.9Check My Knowledge
Phase 2: Detection Library
The methodology module. Before building detection rules, you decide which rules to build first. Crown jewel analysis, threat actor profiling, ATT&CK coverage assessment, risk-based gap scoring, detection backlog, sprint planning, and the 90-day roadmap that DE3 through DE8 execute against.
Show 12 lessonsHide lessons
- 2.1DE2.1 Why Threat Modeling Before Rules
- 2.2DE2.2 Crown Jewel Analysis
- 2.3DE2.3 Threat Actor Profiling and Technique Relevance
- 2.4DE2.4 Current Detection Coverage Baseline
- 2.5DE2.5 Risk-Based Gap Scoring and Data Availability
- 2.6DE2.6 Building the Detection Backlog
- 2.7DE2.7 Sprint Planning and the 90-Day Roadmap
- 2.8DE2.8 Communicating the Program to Leadership
- 2.9DE2.9 Maintaining and Evolving the Backlog
- 2.10DE2.10 Threat Intelligence Integration
- 2.11Module Summary
- 2.12Check My Knowledge
Nine production detection rules for the techniques attackers use to enter your environment. Phishing beyond Safe Links, password spray, AiTM token theft, drive-by compromise, USB and removable media, valid account compromise, attachment-based delivery, and public-facing application exploits, each with annotated KQL, entity mapping, and tuning guidance.
Show 12 lessonsHide lessons
- 3.1DE3.1 The Initial Access Detection Challenge
- 3.2DE3.2 Phishing Detection Beyond Safe Links
- 3.3DE3.3 Sender Reputation and Email Anomaly Detection
- 3.4DE3.4 Password Spray and Distributed Evasion
- 3.5DE3.5 Token Theft and Session Hijacking
- 3.6DE3.6 Drive-By Download and Watering Hole Detection
- 3.7DE3.7 USB and Removable Media Detection
- 3.8DE3.8 Valid Account Compromise Detection
- 3.9DE3.9 Attachment Phishing and Public-Facing Exploits
- 3.10DE3.10 Cross-Chain Correlation and Deployment Strategy
- 3.11Module Summary
- 3.12Check My Knowledge
Identity-layer detection. MFA fatigue, MFA registration anomalies, impossible travel that works with VPN, token replay beyond AiTM, PIM role activation abuse, service principal threats, client secret anomalies, and LSASS credential dumping. Eight production KQL rules targeting the techniques attackers use after initial access to escalate and expand their identity footprint.
Show 14 lessonsHide lessons
- 4.1DE4.1 The Credential Access Challenge
- 4.2DE4.2 MFA Fatigue and Push Bombing Detection
- 4.3DE4.3 MFA Registration from Suspicious Context
- 4.4DE4.4 Impossible Travel That Works with VPN
- 4.5DE4.5 Token Replay Beyond AiTM
- 4.6DE4.6 PIM Role Activation Anomalies
- 4.7DE4.7 Role-to-Action Correlation
- 4.8DE4.8 Service Principal Threat Detection
- 4.9DE4.9 Client Secret and Certificate Anomalies
- 4.10DE4.10 LSASS Credential Dumping Detection
- 4.11DE4.11 Cross-Technique Credential Attack Correlation
- 4.12DE4.12 Credential Attack Deployment and Monitoring
- 4.13Module Summary
- 4.14Check My Knowledge
Post-access detection. Mailbox rules, OAuth consent grants, scheduled tasks, autorun persistence, PowerShell anomalies, local account creation, WMI event subscriptions, file-drop persistence, and execution anomalies. Nine production detection rules across the persistence and execution surface attackers use after initial compromise and credential escalation.
Show 14 lessonsHide lessons
- 5.1DE5.1 The Persistence and Execution Challenge
- 5.2DE5.2 Mailbox Rule Persistence
- 5.3DE5.3 OAuth Consent Grant Persistence
- 5.4DE5.4 Scheduled Task and Service Persistence
- 5.5DE5.5 Autorun Persistence
- 5.6DE5.6 PowerShell Execution Anomaly
- 5.7DE5.7 Local Account Creation
- 5.8DE5.8 WMI Event Subscription Persistence
- 5.9DE5.9 File-Drop Persistence
- 5.10DE5.10 Execution Anomaly
- 5.11DE5.11 Cross-Technique Correlation
- 5.12DE5.12 Deployment and Monitoring
- 5.13Module Summary
- 5.14Check My Knowledge
Mid-chain detection. Reconnaissance command sequences, LDAP enumeration, file and system discovery, Defender tampering, event log clearing, mailbox audit manipulation, security configuration drift, process masquerading, and LOLBin proxy execution. Nine production KQL rules targeting the techniques attackers use to map the environment and hide their activity after establishing persistence.
Show 14 lessonsHide lessons
- 6.1DE6.1 The Discovery and Defense Evasion Challenge
- 6.2DE6.2 Reconnaissance Command Sequence Detection
- 6.3DE6.3 LDAP and Directory Enumeration
- 6.4DE6.4 File and System Discovery Detection
- 6.5DE6.5 Security Tool Tampering Detection
- 6.6DE6.6 Event Log Clearing and Audit Manipulation
- 6.7DE6.7 Mailbox Audit Log Manipulation
- 6.8DE6.8 Security Configuration Drift Monitoring
- 6.9DE6.9 Process Masquerading Detection
- 6.10DE6.10 LOLBin Proxy Execution Detection
- 6.11DE6.11 Cross-Technique Discovery and Evasion Correlation
- 6.12DE6.12 Deployment and Monitoring
- 6.13Module Summary
- 6.14Check My Knowledge
Objective-phase detection. Email collection, SharePoint bulk download, network share access, USB exfiltration, cloud storage upload, time-series anomaly detection, BEC outbound email, C2 beaconing, external sharing abuse, data staging, and archive compression. Eleven production KQL rules detecting how attackers collect target data and move it out of the organization, the phase where the attacker achieves their data theft objective.
Show 16 lessonsHide lessons
- 7.1DE7.1 The Collection and Exfiltration Challenge
- 7.2DE7.2 Email Collection Detection
- 7.3DE7.3 SharePoint and OneDrive Bulk Download Detection
- 7.4DE7.4 Network Share Bulk Access Detection
- 7.5DE7.5 USB Data Exfiltration Detection
- 7.6DE7.6 Cloud Storage Exfiltration Detection
- 7.7DE7.7 Time-Series Anomaly Detection
- 7.8DE7.8 BEC Outbound Email Detection
- 7.9DE7.9 C2 Beaconing and Data Exfiltration Detection
- 7.10DE7.10 External Sharing Abuse Detection
- 7.11DE7.11 Local Data Staging Detection
- 7.12DE7.12 Archive and Compression Detection
- 7.13DE7.13 Cross-Technique Collection Correlation
- 7.14DE7.14 Deployment and Monitoring
- 7.15Module Summary
- 7.16Check My Knowledge
End-chain detection. RDP first-access lateral movement, WMI remote execution, WinRM and PSRemoting, SMB admin share file deployment, cross-site SD-WAN traversal, ransomware pre-encryption indicators, mass file encryption, SSH lateral movement, and service disruption. Nine production KQL rules covering the two final ATT&CK tactics, Lateral Movement and Impact, where the attacker spreads across the network and achieves destructive objectives.
Show 14 lessonsHide lessons
- 8.1DE8.1 The Lateral Movement and Impact Challenge
- 8.2DE8.2 RDP First-Access Lateral Movement
- 8.3DE8.3 WMI Remote Execution Detection
- 8.4DE8.4 WinRM and PSRemoting Detection
- 8.5DE8.5 SMB Admin Share Lateral Movement
- 8.6DE8.6 Cross-Site SD-WAN Traversal Detection
- 8.7DE8.7 Ransomware Pre-Encryption Indicators
- 8.8DE8.8 Mass File Encryption Detection
- 8.9DE8.9 SSH Lateral Movement to Linux Systems
- 8.10DE8.10 Critical Service Stop Detection
- 8.11DE8.11 Cross-Technique Lateral Movement and Impact Correlation
- 8.12DE8.12 Deployment and Monitoring
- 8.13Module Summary
- 8.14Check My Knowledge
Phase 3: Operations
The operational discipline module. Pre-deployment testing against historical data, attack simulation for detection validation, threshold optimization, false positive classification, watchlist and exclusion management, exclusion governance, rule health metrics, the monthly tuning review cadence, tuning case studies, and the detection rule lifecycle from creation through retirement.
Show 13 lessonsHide lessons
- 9.1DE9.1 The Tuning Imperative
- 9.2DE9.2 Testing Before Deployment
- 9.3DE9.3 Attack Simulation and Validation
- 9.4DE9.4 Threshold Optimization
- 9.5DE9.5 False Positive Classification
- 9.6DE9.6 Watchlists and Exclusions
- 9.7DE9.7 Exclusion Governance
- 9.8DE9.8 Rule Health Metrics
- 9.9DE9.9 The Monthly Tuning Review
- 9.10DE9.10 Tuning Case Studies
- 9.11DE9.11 The Tuning Lifecycle
- 9.12Module Summary
- 9.13Check My Knowledge
The engineering maturity module. Portal governance failures, detection-as-code with Git, rule specification standards, CI/CD deployment pipelines, branch strategy and PR review, automated ATT&CK coverage reporting, detection engineering sprints, cross-team collaboration, program metrics, operational cadences, Sigma portability, and Sentinel cost optimization.
Show 14 lessonsHide lessons
- 10.1DE10.1 The Portal Governance Problem
- 10.2DE10.2 Detection-as-Code with Git
- 10.3DE10.3 The Rule Specification Standard
- 10.4DE10.4 CI/CD for Detection Rules
- 10.5DE10.5 Branch Strategy and Pull Request Review
- 10.6DE10.6 Coverage Reporting and ATT&CK Heatmaps
- 10.7DE10.7 The Detection Engineering Sprint
- 10.8DE10.8 Cross-Team Collaboration
- 10.9DE10.9 Program Metrics and Executive Reporting
- 10.10DE10.10 The Detection Engineer Operational Cadence
- 10.11DE10.11 SIGMA Rule Portability
- 10.12DE10.12 Sentinel Cost Optimization
- 10.13Module Summary
- 10.14Check My Knowledge
The capstone module. You run a complete 90-day detection engineering program as Rachel Okafor, NE's CISO, threat modeling, three detection sprints (credential, persistence/movement, collection/impact), ATT&CK coverage assessment, board reporting, a simulated triage day, gap retrospective, and program sustainability planning.
Show 11 lessonsHide lessons
- 11.1DE11.1 Capstone Briefing: The Board Mandate
- 11.2DE11.2 Phase 1: Credential Attack Detection Sprint
- 11.3DE11.3 Phase 2: Persistence and Movement Sprint
- 11.4DE11.4 Phase 3: Collection, Exfiltration, and Config Sprint
- 11.5DE11.5 Full Coverage Assessment
- 11.6DE11.6 The 90-Day Board Report
- 11.7DE11.7 Triage Day: The Full Alert Queue
- 11.8DE11.8 The Detection Gap Retrospective
- 11.9DE11.9 Program Sustainability and Handover
- 11.10Module Summary
- 11.11Check My Knowledge
AI as a detection engineering accelerator. Converting threat advisories to hypotheses, KQL development and debugging, rule specification generation, false positive analysis, Sigma conversion, simulation planning, coverage gap analysis, the end-to-end AI-augmented workflow, and the limitations where human judgment remains irreplaceable.
Show 12 lessonsHide lessons
- 12.1DE12.1 The AI Acceleration Thesis
- 12.2DE12.2 Threat Advisory to Detection Hypothesis
- 12.3DE12.3 KQL Development and Debugging with AI
- 12.4DE12.4 Rule Specification Generation
- 12.5DE12.5 FP Analysis and Tuning Acceleration
- 12.6DE12.6 AI-Assisted SIGMA Conversion
- 12.7DE12.7 AI-Assisted Attack Simulation Planning
- 12.8DE12.8 AI-Assisted Coverage Gap Analysis
- 12.9DE12.9 The AI-Augmented Detection Workflow
- 12.10DE12.10 AI Limitations and the Human Judgment Boundary
- 12.11Module Summary
- 12.12Check My Knowledge
Phase 0: Course Resources
Detection queries by subject area, each with the fields that carry the decision and what the rule will not catch.
The established way to do the recurring things: build a rule, test it, tune it, measure coverage, run a sprint, ship as code, report.
Building an environment you can deploy, test and tune detections in, and the constraint that makes tuning unpractisable in a clean lab.
Show 1 lessonHide lessons
Rules built end to end, including the ones that never fired, fired too much, or reported as coverage while broken.
The established way to get coverage for a threat: the rule set in chain order, what validates it, and where the set is thin.
Show 6 lessonsHide lessons
Resources for building detections and using them at work: a query console, graded investigations, a production detection library, and a DFIR toolkit.
The consolidated lookup and the step-by-step procedures from this course, in one place.
Show 2 lessonsHide lessons
External sources this course draws on: vendor documentation, frameworks, standards, and research.
Course Completion
Threat Detection Engineering end-of-course exam: a three-phase simulation testing whether you can apply the method to a case the course did not walk through.
Show 1 lessonHide lessons
Course overview
This Threat Detection Engineering course equips you with the practical skills to design, build, and operationalize high-fidelity detection capabilities that actually stop threats in cloud, on-prem, and hybrid environments. You'll work hands-on with industry tools including Microsoft Sentinel, Microsoft Defender XDR, and leading open-source technologies to:
By the end, you'll have the confidence and capabilities to protect organizational assets at scale - exactly what modern security teams need from a true threat detection engineer.
How this course works
A detection is a claim that a technique is visible in your data. This course runs the same loop for every rule it builds, and the loop is what makes a rule library into a detection program.
1. Model the threat before writing anything. Which techniques matter to your organization, against your data sources, is a prioritization question. A backlog assembled from a framework rather than from a threat model is a backlog with no order in it.
2. Establish the data source can see it. A rule against a field your estate does not collect is inert and looks identical to a rule that never fires because nothing happened.
3. Write against the durable artifact. The thing the technique cannot avoid doing, rather than the tool that happened to do it this time.
4. Test positively and negatively. Fire the technique and confirm the rule catches it. Run it across normal activity and count what came back. Skipping the second is how alert fatigue is manufactured.
5. Manage it as a lifecycle. Rules decay. Schemas change underneath them, environments change around them, and a rule nobody has re-validated is a coverage claim rather than a control.
The course closes on a ninety-day detection program: not a rule set, an operating model with coverage measured and reviewed.
What this course assumes
No minimum experience and no prerequisite course. KQL, the Sentinel rule model and the ATT&CK framework are all introduced where they first matter.
What makes it go faster: a Sentinel workspace with real data, and any prior query-language exposure. Neither is required, and every rule in the course is written against data the course provides.
What this course does not cover: incident response process, forensics, and SIEM administration. This course builds the detections; investigating what they catch is a separate discipline.
Who this course is for
You're ready to move into (or level up in) threat detection engineering. Whether you're a SOC analyst, security engineer, or experienced defender, this course is designed for you if you want to:
In short: if you want to stop being a passive alert triager and become the engineer who builds the detections that matter, this course is for you.
What you'll learn
By the end of this Threat Detection Engineering course you will be able to:
Key course takeaways
Lab Pack - Threat Detection Engineering Toolkit
Downloadable lab pack covering the full detection engineering lifecycle. Realistic-volume evidence data across 8 Sentinel tables with all 6 attack chains buried in 14 days of legitimate noise, plus detection rules in 6 formats, a Sysmon configuration, threat model artifacts, and program management templates.
Evidence data (~3,500 entries): SigninLogs, AuditLogs, EmailEvents, DeviceProcessEvents, DeviceNetworkEvents, DeviceFileEvents, DeviceRegistryEvents, SysmonEvents with attack indicators hidden in baseline noise.
Detection rules (6 formats, ~80 files): 10 KQL rules, 10 Sigma rules, 5 YARA rules, 30+ auditd rules by tactic, 7 Suricata rules, 7 Velociraptor VQL hunts.
Program artifacts: ATT&CK coverage matrix (30 techniques), NE threat profile, detection-as-code Git structure, FP register with classification guide, 3 tuning case studies, Atomic Red Team test mapping, Sysmon config.
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches detection engineering from first principles. Familiarity with KQL syntax and the Microsoft security stack will help you move faster through the early modules, but neither is required. Every concept is explained at first use.
What are the device requirements?
A device with at least 8 GB of RAM. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) or a production Sentinel workspace for hands-on rule deployment. The lab pack provides synthetic data if you cannot use a live environment.
How will the course benefit your career?
Detection engineering is one of the fastest-growing disciplines in cybersecurity. Organizations need people who can build custom detection rules, not just triage vendor alerts. This course gives you the skills to write production detection rules, operate a detection-as-code pipeline, and measure detection coverage, capabilities that are directly applicable in detection engineering, SOC, threat hunting, and security operations roles.
The demand for engineers who can build and maintain detection programs continues to grow as organizations move beyond vendor-provided templates to custom, threat-informed detection.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy detection rules in your organization's production Sentinel workspace. You may not redistribute course content or share account credentials.
Detection rules: Provided as-is for deployment. Test every rule against your environment's data before enabling in production.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.