Table of Contents

This course joins detection engineering with incident response. You will define observable behavior, write testable logic, investigate synthetic evidence, choose response actions, and record improvements.

The course uses a fictional compromise across identity, endpoint, and DNS logs. Every conclusion must point to evidence. Every response step must state an owner, approval boundary, and verification check.

Audience

This course serves junior security analysts, system administrators moving into security operations, and detection engineers who need a repeatable investigation method.

You should know basic command-line navigation and JSON. Prior SIEM, EDR, or forensic experience is optional.

Outcomes

By the end, you will produce:

  • A telemetry inventory with fields, retention needs, and trust limits
  • An ATT&CK-informed detection hypothesis tied to current Detection Strategies and Analytics
  • A portable rule specification with test cases and tuning notes
  • A full incident timeline built from three synthetic log sources
  • A scope statement separating confirmed impact, likely impact, and unknowns
  • A response plan with containment, recovery, and improvement checks

Course Order

#LessonSkill and output
1Telemetry and EvidenceNormalize events and record source limits
2ATT&CK Detection StrategiesMap behavior without treating ATT&CK as proof
3Detection Hypotheses and RulesWrite logic, tests, and tuning criteria
4Triage and ScopingDecide severity and find related activity
5Full Investigation LabBuild a supported timeline from sample data
6Containment and RecoveryPlan safe response and verify restoration
7Quiz and Answer KeyCheck concepts and evidence handling
8Capstone and Answer KeyDeliver a detection and incident package

Work in order. Lessons 3 through 6 reuse the same event story, so skipped steps leave evidence gaps.

Prerequisites

  • Python 3 for optional JSON parsing
  • jq for command-line JSON filters, or a text editor with JSON support
  • A clean working folder for evidence copies and analyst notes
  • Forty-five to sixty minutes per lesson and ninety minutes for the capstone

Download the data README , authentication events , endpoint events , and DNS events . Save all four files in one folder. Do not alter the source files.

Working Method

  1. Record the question before searching.
  2. Preserve source timestamps and time zones.
  3. Separate observations from analyst conclusions.
  4. Mark missing evidence as unknown.
  5. Test alternate explanations.
  6. Verify each containment and recovery action.

Expected Result: your final report lets another analyst reproduce the timeline and reach the same supported findings.

Current Framework Note

MITRE ATT&CK v19.2 is current as of October 10, 2026. ATT&CK deprecated Data Sources in v18. Use current Detection Strategies, platform-specific Analytics, and Data Components when planning detections. Legacy Data Source pages remain available for reference.

Incident response guidance also changed. NIST SP 800-61 Rev. 3, published in April 2025, places response inside the broader Cybersecurity Framework 2.0 risk cycle. Preparation, detection, response, recovery, and improvement operate as connected activities.

Primary references, checked 2026-10-10: MITRE ATT&CK version history , MITRE ATT&CK Detection Strategies , MITRE ATT&CK Analytics , and NIST SP 800-61 Rev. 3 .

Troubleshooting

  • The data files open in a browser: save the raw files into one working folder.
  • A lesson result differs: compare timestamps, event IDs, and stated assumptions.
  • A tool is missing: use a text editor and preserve the same evidence fields.

Verify Readiness

  • All three event files and the README are present
  • Source files have recorded hashes
  • UTC is the timeline standard
  • Analyst notes use a separate file

Expected Result: the working folder contains preserved evidence, stable hashes, and an empty analyst timeline ready for Lesson 1.

Start Here

Begin with Lesson 1: Telemetry and Evidence . Create the evidence inventory before writing a rule or naming an incident.