Threat Detection & Incident Triage
Work an alert the way a SOC does: detection logic mapped to MITRE ATT&CK, triage that separates real threats from noise, and the containment and report that close it out.
Tuition
$349
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
9 hours
Estimated time
What you will be able to do
- Explain how detections are produced across SIEM, EDR/XDR, NDR and SOAR, and what each log source can and cannot see
- Read a detection use-case and map it to the MITRE ATT&CK tactics and techniques it covers
- Triage an alert end to end: enrich it, pivot across data sources and reconstruct what actually happened
- Reach a defensible true-positive or false-positive verdict and assign the right severity
- Apply escalation criteria and hand an incident off cleanly to the next tier
- Take correct first-response containment actions while preserving evidence and chain of custody
- Write an incident report with a clear timeline, impact assessment and recommendations, aligned to NIST SP 800-61
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
How Detection Works
Trace the detection pipeline from raw telemetry to a fired alert: the log sources and sensors a SOC runs (SIEM, EDR/XDR, NDR, SOAR), how signature, behavioral, and anomaly detection differ, and how to read an alert and locate yourself in the tiered SOC workflow.
2 lessons · 5 quiz questions
- 02
Detection Logic & MITRE ATT&CK
Map detection use-cases to the MITRE ATT&CK framework, reason about coverage and durability with the Pyramid of Pain, and read, write, and tune vendor-neutral Sigma detection rules so you can state exactly which adversary behaviors you cover and where the gaps are.
2 lessons · 5 quiz questions · assignment
- 03
Triaging an Alert End to End
Turns a single ambiguous alert into a defensible verdict. You will run a repeatable triage workflow - understanding the detection, enriching its indicators, pivoting across data sources, and reconstructing the sequence of events - then decide true versus false positive and set a severity you can justify to an IR lead or auditor.
2 lessons · 5 quiz questions
- 04
Escalate, Contain & Report
A confirmed threat has to move fast and cleanly. This module teaches when and how to escalate, the first-response containment actions a SOC analyst can safely take (isolating a host, disabling an account, blocking an indicator) while preserving evidence and chain of custody, and how to write the incident report that hands the story to responders and leadership. It is aligned to the NIST SP 800-61 incident handling lifecycle.
2 lessons · 5 quiz questions · assignment