Gain hands-on skills in Detection Engineering and SIEM, learning the processes for understanding logs, enhancing existing logging solutions, and creating detection content that fits your needs. Covers SIEM architecture, network and endpoint analytics, cloud logging in AWS and Azure, MITRE ATT&CK mapping, and automated detection pipelines.
Master Detection Engineering and SIEM analytics to identify adversaries hiding in your environment. Transform security data into actionable intelligence through hands-on training.
What You Will Learn:
Detection Engineering Fundamentals
Build and configure detection lab environments
Write detection rules to identify adversary behaviors
Optimize SIEM architecture for performance and visibility
Perform adversary emulation and analyze log activity
18 hands-on labs include MITRE DeTT&CT gap analysis, DNS log investigation, HTTP log analysis, Windows log examination, inventory-based threat hunting, Azure cloud logging, AWS lab configuration, Sigma coverage analysis, and a Defend-the-Flag team challenge.
The course culminates in a team-based design, detect, and defend the flag competition covering logging architecture, log augmentation, network and system log analysis, and dashboard development.
Prepares for GIAC GCDA certification (exam sold separately). Ideal for SOC Analysts, Detection Analysts, Security Engineers, and Threat Hunters.
30 CPE credits. 5 days of expert-led training.
Highlights
Build and configure your own detection lab environment. Write detection rules to identify adversary behaviors. Optimize SIEM architecture for better performance and visibility. Perform adversary emulation and analyze related log activity
Comprehensive hands-on training with 18 practical labs covering: Using MITRE DeTT&CT to Identify Monitoring Gaps, Investigating DNS Logs, Investigating DNS Logs, Using inventory data for threat hunting, Using inventory data for threat hunting, Logging Unauthorized Access to Sensitive Data, Logging Unauthorized Access to Sensitive Data, Identify Log Gaps and Compare With Sigma Coverage and 1 more exercises
Certification: Prepares for GCDA. Earn 30 CPE credits. 5 days of intensive training. Business outcomes: Identify and mitigate threats in near real-time to reduce business risk
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing has one pricing dimension: a single-user license for the SEC555: Detection Engineering & SIEM Analytics course. You buy it as a contract for one learner. Pricing covers access for that individual only. There are no tiers, instance sizes, or usage add-ons to choose from. If you need to train more than one person, you would purchase additional single-user licenses. The unit is per user, so cost scales with the number of learners you enroll.
Top-of-mind questions for buyers
What does one single-user license cover, and how long can that person access the course?
One license covers one named learner for the SEC555 course. Self-paced OnDemand access typically runs for a set period, commonly four months. Extensions may be requested through SANS if you cannot finish in the standard window. Access is tied to that individual and is not shared between people.
Can I share one license across a team, or transfer it to another employee?
No. Each single-user license grants access to one person only. Course material and access are personal and not shared. To train multiple people, you buy additional single-user licenses, one per learner. Cost scales directly with the number of people you enroll.
Does the single-user license include the GIAC certification exam or hands-on labs?
The license covers course access, which includes hands-on labs as part of the training material. The associated GIAC certification is a separate item and is not required to complete the course. If you want the exam, you would arrange that separately from this course license.
www.sans.org
Helpful?
Vendor refund policy
Refunds available within 30 days if course not accessed.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Protect your dynamic cloud environments with consistent security, superior visibility, and advanced threat defense such as application visibility and control, deep packet inspection, IPS, malware defense, and URL filtering - powered by Cisco Talos® Threat Intelligence. Achieve deeper visibility into QUIC and TLS 1.3 traffic without breaking Layer 7 policies.
Protect your dynamic cloud environments with consistent security, superior visibility, and advanced threat defense such as application visibility and control, deep packet inspection, IPS, malware defense, and URL filtering - powered by Cisco Talos® Threat Intelligence. Achieve deeper visibility into QUIC and TLS 1.3 traffic without breaking Layer 7 policies.
Infoblox Threat Defense delivers preemptive DNS security to stop malware, ransomware, command-and-control (C2) communications, and DNS-based data exfiltration before they impact users or cloud workloads. It enriches SIEM, SOAR, and SOC operations with threat intelligence and automation.
Cloud Defense offers a revolutionary solution to discovering and protecting sensitive data in public cloud from modern ransomware and exfiltration attacks.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.