Resolv Academy · Programme
Security Operations
Detection, response and threat hunting, practised against realistic attack activity in a lab environment.
- Length
- 10 weeks
- Level
- Intermediate
- Format
- Instructor-led, live online or on-site, with a simulated enterprise environment for detection and response exercises
- Certification
- Aligned to the objectives of CompTIA Security+ and CompTIA CySA+.
Who it is for
- IT staff moving into security operations
- Junior security analysts
- Network and system administrators responsible for security monitoring
Prerequisites
- Working knowledge of networking and operating systems
- Familiarity with common security concepts
You will be able to
- Triage alerts and distinguish true from false positives
- Investigate incidents using logs, endpoint and network data
- Write and tune detection rules
- Contain incidents and document them for review
- Conduct hypothesis-led threat hunts
Syllabus
Module by module.
- Module 01
Security operations fundamentals
- Role of the security operations centre
- Threats, vulnerabilities and risk
- Common attack lifecycles
- MITRE ATT&CK as a common language
- Module 02
Logging and telemetry
- Log sources that matter
- Centralised logging and SIEM concepts
- Endpoint telemetry
- Retention and integrity of logs
- Module 03
Alert triage
- Prioritisation and severity
- Enrichment and context
- Escalation and handover
- Module 04
Investigation
- Endpoint investigation
- Network traffic analysis
- Identity and authentication events
- Building a timeline
- Module 05
Detection engineering
- Writing detection rules
- Testing detections against simulated activity
- Tuning to reduce noise
- Module 06
Incident response
- Preparation and playbooks
- Containment, eradication and recovery
- Evidence handling
- Post-incident review
- Module 07
Threat hunting
- Hypothesis-led hunting
- Using threat intelligence
- Turning hunts into detections
Hands-on labs
Learning by operating real systems.
- Lab 01
Triage a queue of alerts from a simulated enterprise
- Lab 02
Investigate a phishing-led compromise from initial access to lateral movement
- Lab 03
Write and test detection rules for credential abuse
- Lab 04
Contain a simulated ransomware outbreak and document the response
- Lab 05
Run a threat hunt and convert the findings into detections
Reserve a place or book a private cohort.
A senior engineer reviews every enquiry and replies within one business day.