RESOLV

Train · Resolv Academy

Security operations

Hands-on training in detection, triage, incident handling and threat hunting, delivered in a realistic simulated security operations centre.

The challenge

Security analysts are hard to hire and slow to develop. Many new analysts learn on live alerts, where mistakes are expensive and good habits form slowly.

Theory-heavy courses produce people who can describe the kill chain but freeze when faced with a real alert queue and incomplete information.

Our programme puts participants in a simulated operations centre with real tooling and staged attacks, so they build investigation habits before they need them in production.

Our method

How the work is done.

  1. 01

    Foundations

    Networking, operating system internals, logging and the attacker techniques catalogued in MITRE ATT&CK.

  2. 02

    Tooling

    Participants work with SIEM, endpoint detection and network analysis tools, writing and tuning their own detection rules.

  3. 03

    Simulated operations

    Staged attacks run through the lab environment while participants triage alerts, investigate and escalate under time pressure.

  4. 04

    Incident handling

    Exercises follow the NIST SP 800-61 lifecycle, including evidence handling and written incident reports.

  5. 05

    Assessment

    A graded capstone investigation and knowledge checks aligned to CompTIA Security+ and CySA+ objectives.

Deliverables

What you receive.

  • Instructor-led sessions with practising security engineers
  • Access to a simulated operations centre lab environment
  • Detection rules and playbooks written by participants during the course
  • Capstone investigation report with graded feedback
  • Individual assessment results
  • Cohort summary for the sponsoring organisation
  • Certificate of completion

Engagement options

Ways to buy it.

  1. 01

    Open cohort

    Scheduled programme for individuals.

    10 weeks, part-time
  2. 02

    Private cohort

    Delivered to one organisation, with scenarios adapted to its tooling and threats.

    6 to 10 weeks
  3. 03

    Team exercise

    A focused simulated-attack exercise for an existing operations team.

    1 to 3 days

Standards

Frameworks we work to.

  • MITRE ATT&CK
  • NIST SP 800-61
  • Aligned to CompTIA Security+
  • Aligned to CompTIA CySA+

Questions

What buyers ask us.

Is this suitable for complete beginners?

Participants need IT fundamentals. Those new to IT should start with a foundation programme first.

Which tools are used in the labs?

A mix of widely used commercial and open-source SIEM, endpoint and network tools. Private cohorts can use your own platform where licensing allows.

Can the exercise be run against our real environment?

Training exercises run in an isolated lab. For live testing of your team, we combine training with a controlled exercise designed alongside our detection and response practice.

Are certification exams included?

The programme is aligned to the certification objectives; exams are booked separately.

Discuss security operations.

A senior engineer reviews every enquiry and replies within one business day.