Detection Engineering and Incident Response Course
Table of Contents
This course joins detection engineering with incident response. You will define observable behavior, write testable logic, investigate synthetic evidence, choose response actions, and record improvements.
The course uses a fictional compromise across identity, endpoint, and DNS logs. Every conclusion must point to evidence. Every response step must state an owner, approval boundary, and verification check.
Audience
This course serves junior security analysts, system administrators moving into security operations, and detection engineers who need a repeatable investigation method.
You should know basic command-line navigation and JSON. Prior SIEM, EDR, or forensic experience is optional.
Outcomes
By the end, you will produce:
- A telemetry inventory with fields, retention needs, and trust limits
- An ATT&CK-informed detection hypothesis tied to current Detection Strategies and Analytics
- A portable rule specification with test cases and tuning notes
- A full incident timeline built from three synthetic log sources
- A scope statement separating confirmed impact, likely impact, and unknowns
- A response plan with containment, recovery, and improvement checks
Course Order
| # | Lesson | Skill and output |
|---|---|---|
| 1 | Telemetry and Evidence | Normalize events and record source limits |
| 2 | ATT&CK Detection Strategies | Map behavior without treating ATT&CK as proof |
| 3 | Detection Hypotheses and Rules | Write logic, tests, and tuning criteria |
| 4 | Triage and Scoping | Decide severity and find related activity |
| 5 | Full Investigation Lab | Build a supported timeline from sample data |
| 6 | Containment and Recovery | Plan safe response and verify restoration |
| 7 | Quiz and Answer Key | Check concepts and evidence handling |
| 8 | Capstone and Answer Key | Deliver a detection and incident package |
Work in order. Lessons 3 through 6 reuse the same event story, so skipped steps leave evidence gaps.
Prerequisites
- Python 3 for optional JSON parsing
jqfor command-line JSON filters, or a text editor with JSON support- A clean working folder for evidence copies and analyst notes
- Forty-five to sixty minutes per lesson and ninety minutes for the capstone
Download the data README , authentication events , endpoint events , and DNS events . Save all four files in one folder. Do not alter the source files.
Working Method
- Record the question before searching.
- Preserve source timestamps and time zones.
- Separate observations from analyst conclusions.
- Mark missing evidence as unknown.
- Test alternate explanations.
- Verify each containment and recovery action.
Expected Result: your final report lets another analyst reproduce the timeline and reach the same supported findings.
Current Framework Note
MITRE ATT&CK v19.2 is current as of October 10, 2026. ATT&CK deprecated Data Sources in v18. Use current Detection Strategies, platform-specific Analytics, and Data Components when planning detections. Legacy Data Source pages remain available for reference.
Incident response guidance also changed. NIST SP 800-61 Rev. 3, published in April 2025, places response inside the broader Cybersecurity Framework 2.0 risk cycle. Preparation, detection, response, recovery, and improvement operate as connected activities.
Primary references, checked 2026-10-10: MITRE ATT&CK version history , MITRE ATT&CK Detection Strategies , MITRE ATT&CK Analytics , and NIST SP 800-61 Rev. 3 .
Troubleshooting
- The data files open in a browser: save the raw files into one working folder.
- A lesson result differs: compare timestamps, event IDs, and stated assumptions.
- A tool is missing: use a text editor and preserve the same evidence fields.
Verify Readiness
- All three event files and the README are present
- Source files have recorded hashes
- UTC is the timeline standard
- Analyst notes use a separate file
Expected Result: the working folder contains preserved evidence, stable hashes, and an empty analyst timeline ready for Lesson 1.
Start Here
Begin with Lesson 1: Telemetry and Evidence . Create the evidence inventory before writing a rule or naming an incident.


