Train · Resolv Academy
Security operations
Hands-on training in detection, triage, incident handling and threat hunting, delivered in a realistic simulated security operations centre.
The challenge
Security analysts are hard to hire and slow to develop. Many new analysts learn on live alerts, where mistakes are expensive and good habits form slowly.
Theory-heavy courses produce people who can describe the kill chain but freeze when faced with a real alert queue and incomplete information.
Our programme puts participants in a simulated operations centre with real tooling and staged attacks, so they build investigation habits before they need them in production.
Our method
How the work is done.
- 01
Foundations
Networking, operating system internals, logging and the attacker techniques catalogued in MITRE ATT&CK.
- 02
Tooling
Participants work with SIEM, endpoint detection and network analysis tools, writing and tuning their own detection rules.
- 03
Simulated operations
Staged attacks run through the lab environment while participants triage alerts, investigate and escalate under time pressure.
- 04
Incident handling
Exercises follow the NIST SP 800-61 lifecycle, including evidence handling and written incident reports.
- 05
Assessment
A graded capstone investigation and knowledge checks aligned to CompTIA Security+ and CySA+ objectives.
Deliverables
What you receive.
- Instructor-led sessions with practising security engineers
- Access to a simulated operations centre lab environment
- Detection rules and playbooks written by participants during the course
- Capstone investigation report with graded feedback
- Individual assessment results
- Cohort summary for the sponsoring organisation
- Certificate of completion
Engagement options
Ways to buy it.
- 0110 weeks, part-time
Open cohort
Scheduled programme for individuals.
- 026 to 10 weeks
Private cohort
Delivered to one organisation, with scenarios adapted to its tooling and threats.
- 031 to 3 days
Team exercise
A focused simulated-attack exercise for an existing operations team.
Standards
Frameworks we work to.
- MITRE ATT&CK
- NIST SP 800-61
- Aligned to CompTIA Security+
- Aligned to CompTIA CySA+
Questions
What buyers ask us.
Is this suitable for complete beginners?
Participants need IT fundamentals. Those new to IT should start with a foundation programme first.
Which tools are used in the labs?
A mix of widely used commercial and open-source SIEM, endpoint and network tools. Private cohorts can use your own platform where licensing allows.
Can the exercise be run against our real environment?
Training exercises run in an isolated lab. For live testing of your team, we combine training with a controlled exercise designed alongside our detection and response practice.
Are certification exams included?
The programme is aligned to the certification objectives; exams are booked separately.
Related services
Often delivered together.
Secure
Managed detection & response
Continuous monitoring of your endpoints, identities, networks and cloud, with analysts who triage alerts and contain threats under agreed playbooks.
Secure
Incident response
Investigation, containment and recovery when a breach is suspected or confirmed, run to NIST SP 800-61 and documented for regulators and insurers.
Train
Enterprise networking
Routing, switching, wireless and network security taught through hands-on labs on real and virtual equipment.
Discuss security operations.
A senior engineer reviews every enquiry and replies within one business day.