Threat Detection Engineering

Master Threat Detection Engineering

Design, build, and operationalize advanced detection capabilities that actually stop modern threats across on-prem and cloud environments.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Build detection capabilities that transform your security capabilities from reactive alert triage to proactive threat detection
✓Respond to new threat advisories by developing, testing, and deploying validated detections
✓Develop and maintain detection capabilities and manage detection programs that meet organizational requirements with confidence
✓Manage the full detection lifecycle from development through tuning to retirement
✓Develop structured analytical techniques for detection engineering and security operations
SEC401 | Premium tier | 13 modules across 3 phases | 36–40 hours at your own pace | 40 CPE credits | All tools free

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Foundations

Module 1Detection Rule Architecture in Microsoft Sentinel

How detection rules work architecturally in Sentinel and Defender XDR. The five-stage scheduled rule pipeline, entity mapping, alert enrichment, severity classification, ATT&CK coverage mapping, NRT rules, Defender XDR custom detections, alert grouping, incident architecture, and the rule specification template. You configure and deploy a production detection rule with every parameter set deliberately.

Show 9 lessonsHide lessons
  1. 1.1DE1.1 Sentinel Analytics Rule Types
  2. 1.2DE1.2 Anatomy of a Scheduled Rule
  3. 1.3DE1.3 Entity Mapping and Alert Enrichment
  4. 1.4DE1.4 Severity, MITRE Mapping, and Documentation
  5. 1.5DE1.5 NRT Rules and Defender XDR Custom Detections
  6. 1.6DE1.6 Alert Grouping and Incident Architecture
  7. 1.7DE1.7 The Rule Specification Template and Common Mistakes
  8. 1.8Module Summary
  9. 1.9Check My Knowledge

Phase 2: Detection Library

Module 3Detecting Initial Access

Nine production detection rules for the techniques attackers use to enter your environment. Phishing beyond Safe Links, password spray, AiTM token theft, drive-by compromise, USB and removable media, valid account compromise, attachment-based delivery, and public-facing application exploits, each with annotated KQL, entity mapping, and tuning guidance.

Show 12 lessonsHide lessons
  1. 3.1DE3.1 The Initial Access Detection Challenge
  2. 3.2DE3.2 Phishing Detection Beyond Safe Links
  3. 3.3DE3.3 Sender Reputation and Email Anomaly Detection
  4. 3.4DE3.4 Password Spray and Distributed Evasion
  5. 3.5DE3.5 Token Theft and Session Hijacking
  6. 3.6DE3.6 Drive-By Download and Watering Hole Detection
  7. 3.7DE3.7 USB and Removable Media Detection
  8. 3.8DE3.8 Valid Account Compromise Detection
  9. 3.9DE3.9 Attachment Phishing and Public-Facing Exploits
  10. 3.10DE3.10 Cross-Chain Correlation and Deployment Strategy
  11. 3.11Module Summary
  12. 3.12Check My Knowledge
Module 5Detecting Persistence and Execution

Post-access detection. Mailbox rules, OAuth consent grants, scheduled tasks, autorun persistence, PowerShell anomalies, local account creation, WMI event subscriptions, file-drop persistence, and execution anomalies. Nine production detection rules across the persistence and execution surface attackers use after initial compromise and credential escalation.

Show 14 lessonsHide lessons
  1. 5.1DE5.1 The Persistence and Execution Challenge
  2. 5.2DE5.2 Mailbox Rule Persistence
  3. 5.3DE5.3 OAuth Consent Grant Persistence
  4. 5.4DE5.4 Scheduled Task and Service Persistence
  5. 5.5DE5.5 Autorun Persistence
  6. 5.6DE5.6 PowerShell Execution Anomaly
  7. 5.7DE5.7 Local Account Creation
  8. 5.8DE5.8 WMI Event Subscription Persistence
  9. 5.9DE5.9 File-Drop Persistence
  10. 5.10DE5.10 Execution Anomaly
  11. 5.11DE5.11 Cross-Technique Correlation
  12. 5.12DE5.12 Deployment and Monitoring
  13. 5.13Module Summary
  14. 5.14Check My Knowledge
Module 6Detecting Discovery and Defense Evasion

Mid-chain detection. Reconnaissance command sequences, LDAP enumeration, file and system discovery, Defender tampering, event log clearing, mailbox audit manipulation, security configuration drift, process masquerading, and LOLBin proxy execution. Nine production KQL rules targeting the techniques attackers use to map the environment and hide their activity after establishing persistence.

Show 14 lessonsHide lessons
  1. 6.1DE6.1 The Discovery and Defense Evasion Challenge
  2. 6.2DE6.2 Reconnaissance Command Sequence Detection
  3. 6.3DE6.3 LDAP and Directory Enumeration
  4. 6.4DE6.4 File and System Discovery Detection
  5. 6.5DE6.5 Security Tool Tampering Detection
  6. 6.6DE6.6 Event Log Clearing and Audit Manipulation
  7. 6.7DE6.7 Mailbox Audit Log Manipulation
  8. 6.8DE6.8 Security Configuration Drift Monitoring
  9. 6.9DE6.9 Process Masquerading Detection
  10. 6.10DE6.10 LOLBin Proxy Execution Detection
  11. 6.11DE6.11 Cross-Technique Discovery and Evasion Correlation
  12. 6.12DE6.12 Deployment and Monitoring
  13. 6.13Module Summary
  14. 6.14Check My Knowledge
Module 8Detecting Lateral Movement and Impact

End-chain detection. RDP first-access lateral movement, WMI remote execution, WinRM and PSRemoting, SMB admin share file deployment, cross-site SD-WAN traversal, ransomware pre-encryption indicators, mass file encryption, SSH lateral movement, and service disruption. Nine production KQL rules covering the two final ATT&CK tactics, Lateral Movement and Impact, where the attacker spreads across the network and achieves destructive objectives.

Show 14 lessonsHide lessons
  1. 8.1DE8.1 The Lateral Movement and Impact Challenge
  2. 8.2DE8.2 RDP First-Access Lateral Movement
  3. 8.3DE8.3 WMI Remote Execution Detection
  4. 8.4DE8.4 WinRM and PSRemoting Detection
  5. 8.5DE8.5 SMB Admin Share Lateral Movement
  6. 8.6DE8.6 Cross-Site SD-WAN Traversal Detection
  7. 8.7DE8.7 Ransomware Pre-Encryption Indicators
  8. 8.8DE8.8 Mass File Encryption Detection
  9. 8.9DE8.9 SSH Lateral Movement to Linux Systems
  10. 8.10DE8.10 Critical Service Stop Detection
  11. 8.11DE8.11 Cross-Technique Lateral Movement and Impact Correlation
  12. 8.12DE8.12 Deployment and Monitoring
  13. 8.13Module Summary
  14. 8.14Check My Knowledge

Phase 3: Operations

Module 9Detection Testing, Tuning, and Lifecycle Management

The operational discipline module. Pre-deployment testing against historical data, attack simulation for detection validation, threshold optimization, false positive classification, watchlist and exclusion management, exclusion governance, rule health metrics, the monthly tuning review cadence, tuning case studies, and the detection rule lifecycle from creation through retirement.

Show 13 lessonsHide lessons
  1. 9.1DE9.1 The Tuning Imperative
  2. 9.2DE9.2 Testing Before Deployment
  3. 9.3DE9.3 Attack Simulation and Validation
  4. 9.4DE9.4 Threshold Optimization
  5. 9.5DE9.5 False Positive Classification
  6. 9.6DE9.6 Watchlists and Exclusions
  7. 9.7DE9.7 Exclusion Governance
  8. 9.8DE9.8 Rule Health Metrics
  9. 9.9DE9.9 The Monthly Tuning Review
  10. 9.10DE9.10 Tuning Case Studies
  11. 9.11DE9.11 The Tuning Lifecycle
  12. 9.12Module Summary
  13. 9.13Check My Knowledge
Module 11Capstone: The 90-Day Detection Program

The capstone module. You run a complete 90-day detection engineering program as Rachel Okafor, NE's CISO, threat modeling, three detection sprints (credential, persistence/movement, collection/impact), ATT&CK coverage assessment, board reporting, a simulated triage day, gap retrospective, and program sustainability planning.

Show 11 lessonsHide lessons
  1. 11.1DE11.1 Capstone Briefing: The Board Mandate
  2. 11.2DE11.2 Phase 1: Credential Attack Detection Sprint
  3. 11.3DE11.3 Phase 2: Persistence and Movement Sprint
  4. 11.4DE11.4 Phase 3: Collection, Exfiltration, and Config Sprint
  5. 11.5DE11.5 Full Coverage Assessment
  6. 11.6DE11.6 The 90-Day Board Report
  7. 11.7DE11.7 Triage Day: The Full Alert Queue
  8. 11.8DE11.8 The Detection Gap Retrospective
  9. 11.9DE11.9 Program Sustainability and Handover
  10. 11.10Module Summary
  11. 11.11Check My Knowledge
Module 12AI-Accelerated Detection Engineering

AI as a detection engineering accelerator. Converting threat advisories to hypotheses, KQL development and debugging, rule specification generation, false positive analysis, Sigma conversion, simulation planning, coverage gap analysis, the end-to-end AI-augmented workflow, and the limitations where human judgment remains irreplaceable.

Show 12 lessonsHide lessons
  1. 12.1DE12.1 The AI Acceleration Thesis
  2. 12.2DE12.2 Threat Advisory to Detection Hypothesis
  3. 12.3DE12.3 KQL Development and Debugging with AI
  4. 12.4DE12.4 Rule Specification Generation
  5. 12.5DE12.5 FP Analysis and Tuning Acceleration
  6. 12.6DE12.6 AI-Assisted SIGMA Conversion
  7. 12.7DE12.7 AI-Assisted Attack Simulation Planning
  8. 12.8DE12.8 AI-Assisted Coverage Gap Analysis
  9. 12.9DE12.9 The AI-Augmented Detection Workflow
  10. 12.10DE12.10 AI Limitations and the Human Judgment Boundary
  11. 12.11Module Summary
  12. 12.12Check My Knowledge

Phase 0: Course Resources

ResourcesCookbooks

The established way to do the recurring things: build a rule, test it, tune it, measure coverage, run a sprint, ship as code, report.

Show 7 lessonsHide lessons
  1. 1Building a Rule
  2. 2Testing Before Deployment
  3. 3Tuning a Noisy Rule
  4. 4Measuring Coverage
  5. 5Running a Detection Sprint
  6. 6Shipping Rules as Code
  7. 7The Quarterly Report
ResourcesLab Setup

Building an environment you can deploy, test and tune detections in, and the constraint that makes tuning unpractisable in a clean lab.

Show 1 lessonHide lessons
  1. 1Building the Environment
ResourcesPlaybooks

The established way to get coverage for a threat: the rule set in chain order, what validates it, and where the set is thin.

Show 6 lessonsHide lessons
  1. 1Ransomware
  2. 2Account Takeover
  3. 3Business Email Compromise
  4. 4Insider Data Theft
  5. 5Lateral Movement
  6. 6A Newly Published Technique
ResourcesPlayground

Resources for building detections and using them at work: a query console, graded investigations, a production detection library, and a DFIR toolkit.

ResourcesOperational Reference

The consolidated lookup and the step-by-step procedures from this course, in one place.

Show 2 lessonsHide lessons
  1. 1Detection Rule Quick Reference
  2. 2Detection Engineering Field Manual
ResourcesReferences & Further Reading

External sources this course draws on: vendor documentation, frameworks, standards, and research.

Course Completion

CompletionCourse Exam

Threat Detection Engineering end-of-course exam: a three-phase simulation testing whether you can apply the method to a case the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Threat Detection Engineering

Course overview

This Threat Detection Engineering course equips you with the practical skills to design, build, and operationalize high-fidelity detection capabilities that actually stop threats in cloud, on-prem, and hybrid environments. You'll work hands-on with industry tools including Microsoft Sentinel, Microsoft Defender XDR, and leading open-source technologies to:

✓ Develop a sharp investigative mindset that turns alerts into actionable intelligence
✓ Engineer, test, and deploy production-ready detections across your entire stack
✓ Move from reactive monitoring to proactive, engineering-led threat detection and response

By the end, you'll have the confidence and capabilities to protect organizational assets at scale - exactly what modern security teams need from a true threat detection engineer.

How this course works

A detection is a claim that a technique is visible in your data. This course runs the same loop for every rule it builds, and the loop is what makes a rule library into a detection program.

1. Model the threat before writing anything. Which techniques matter to your organization, against your data sources, is a prioritization question. A backlog assembled from a framework rather than from a threat model is a backlog with no order in it.

2. Establish the data source can see it. A rule against a field your estate does not collect is inert and looks identical to a rule that never fires because nothing happened.

3. Write against the durable artifact. The thing the technique cannot avoid doing, rather than the tool that happened to do it this time.

4. Test positively and negatively. Fire the technique and confirm the rule catches it. Run it across normal activity and count what came back. Skipping the second is how alert fatigue is manufactured.

5. Manage it as a lifecycle. Rules decay. Schemas change underneath them, environments change around them, and a rule nobody has re-validated is a coverage claim rather than a control.

The course closes on a ninety-day detection program: not a rule set, an operating model with coverage measured and reviewed.

What this course assumes

No minimum experience and no prerequisite course. KQL, the Sentinel rule model and the ATT&CK framework are all introduced where they first matter.

What makes it go faster: a Sentinel workspace with real data, and any prior query-language exposure. Neither is required, and every rule in the course is written against data the course provides.

What this course does not cover: incident response process, forensics, and SIEM administration. This course builds the detections; investigating what they catch is a separate discipline.

Who this course is for

You're ready to move into (or level up in) threat detection engineering. Whether you're a SOC analyst, security engineer, or experienced defender, this course is designed for you if you want to:

✓ Develop a sharp investigative mindset that turns raw alerts into actionable intelligence
✓ Master how to design, build, and operationalize high-fidelity detection capabilities
✓ Confidently analyze, deploy, and run detections that actually work across on-prem, cloud, and hybrid environments
✓ Protect organizational assets with engineering-level precision instead of just monitoring

In short: if you want to stop being a passive alert triager and become the engineer who builds the detections that matter, this course is for you.

What you'll learn

By the end of this Threat Detection Engineering course you will be able to:

✓ Assess your current defenses against the techniques attackers are actually using, and engineer high-fidelity detections that hold up
✓ Apply the MITRE ATT&CK framework to build threat-informed, proactive detection strategies
✓ Proactively hunt threats across networks, endpoints, cloud, and hybrid environments using advanced tools and techniques
✓ Build complete visibility into hybrid, decentralized, and encrypted infrastructure
✓ Design, analyze, and operationalize detections with Microsoft Defender XDR, Microsoft Sentinel, endpoint tools, and leading SIEM platforms
✓ Secure identities, harden endpoints, and transform SOC operations from reactive monitoring to engineering-led threat detection

Key course takeaways

✓ Build repeatable, high-fidelity detection strategies that hold across cloud, on-prem, network, and hybrid environments
✓ Engineer and operationalize production-grade threat detection and response capabilities organizations can actually rely on
✓ Apply threat-informed defense (MITRE ATT&CK) to continuously optimize and mature your security operations
✓ Proactively identify, close, and eliminate protection gaps before attackers can exploit them
✓ Maximize your existing tools and infrastructure - including Microsoft Sentinel, Defender XDR, and open-source solutions - for maximum detection impact
✓ Transform your SOC from reactive alert triage into a proactive, engineering-driven threat detection powerhouse

Lab Pack - Threat Detection Engineering Toolkit

Downloadable lab pack covering the full detection engineering lifecycle. Realistic-volume evidence data across 8 Sentinel tables with all 6 attack chains buried in 14 days of legitimate noise, plus detection rules in 6 formats, a Sysmon configuration, threat model artifacts, and program management templates.

Evidence data (~3,500 entries): SigninLogs, AuditLogs, EmailEvents, DeviceProcessEvents, DeviceNetworkEvents, DeviceFileEvents, DeviceRegistryEvents, SysmonEvents with attack indicators hidden in baseline noise.

Detection rules (6 formats, ~80 files): 10 KQL rules, 10 Sigma rules, 5 YARA rules, 30+ auditd rules by tactic, 7 Suricata rules, 7 Velociraptor VQL hunts.

Program artifacts: ATT&CK coverage matrix (30 techniques), NE threat profile, detection-as-code Git structure, FP register with classification guide, 3 tuning case studies, Atomic Red Team test mapping, Sysmon config.

Threat Detection Engineering Lab Pack
~80 files · 6 rule formats · ~3,500 evidence entries · Sysmon config · ATT&CK coverage matrix
Download Lab Pack (.zip)

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches detection engineering from first principles. Familiarity with KQL syntax and the Microsoft security stack will help you move faster through the early modules, but neither is required. Every concept is explained at first use.

What are the device requirements?

A device with at least 8 GB of RAM. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) or a production Sentinel workspace for hands-on rule deployment. The lab pack provides synthetic data if you cannot use a live environment.

How will the course benefit your career?

Detection engineering is one of the fastest-growing disciplines in cybersecurity. Organizations need people who can build custom detection rules, not just triage vendor alerts. This course gives you the skills to write production detection rules, operate a detection-as-code pipeline, and measure detection coverage, capabilities that are directly applicable in detection engineering, SOC, threat hunting, and security operations roles.

The demand for engineers who can build and maintain detection programs continues to grow as organizations move beyond vendor-provided templates to custom, threat-informed detection.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy detection rules in your organization's production Sentinel workspace. You may not redistribute course content or share account credentials.

Detection rules: Provided as-is for deployment. Test every rule against your environment's data before enabling in production.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
3scenarios
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.