RESOLV

Resolv Academy · Programme

Security Operations

Detection, response and threat hunting, practised against realistic attack activity in a lab environment.

Length
10 weeks
Level
Intermediate
Format
Instructor-led, live online or on-site, with a simulated enterprise environment for detection and response exercises
Certification
Aligned to the objectives of CompTIA Security+ and CompTIA CySA+.

Who it is for

  • IT staff moving into security operations
  • Junior security analysts
  • Network and system administrators responsible for security monitoring

Prerequisites

  • Working knowledge of networking and operating systems
  • Familiarity with common security concepts

You will be able to

  • Triage alerts and distinguish true from false positives
  • Investigate incidents using logs, endpoint and network data
  • Write and tune detection rules
  • Contain incidents and document them for review
  • Conduct hypothesis-led threat hunts

Syllabus

Module by module.

  1. Module 01

    Security operations fundamentals

    • Role of the security operations centre
    • Threats, vulnerabilities and risk
    • Common attack lifecycles
    • MITRE ATT&CK as a common language
  2. Module 02

    Logging and telemetry

    • Log sources that matter
    • Centralised logging and SIEM concepts
    • Endpoint telemetry
    • Retention and integrity of logs
  3. Module 03

    Alert triage

    • Prioritisation and severity
    • Enrichment and context
    • Escalation and handover
  4. Module 04

    Investigation

    • Endpoint investigation
    • Network traffic analysis
    • Identity and authentication events
    • Building a timeline
  5. Module 05

    Detection engineering

    • Writing detection rules
    • Testing detections against simulated activity
    • Tuning to reduce noise
  6. Module 06

    Incident response

    • Preparation and playbooks
    • Containment, eradication and recovery
    • Evidence handling
    • Post-incident review
  7. Module 07

    Threat hunting

    • Hypothesis-led hunting
    • Using threat intelligence
    • Turning hunts into detections

Hands-on labs

Learning by operating real systems.

  • Lab 01

    Triage a queue of alerts from a simulated enterprise

  • Lab 02

    Investigate a phishing-led compromise from initial access to lateral movement

  • Lab 03

    Write and test detection rules for credential abuse

  • Lab 04

    Contain a simulated ransomware outbreak and document the response

  • Lab 05

    Run a threat hunt and convert the findings into detections

Reserve a place or book a private cohort.

A senior engineer reviews every enquiry and replies within one business day.