
Place security tools into the four jobs—collect, detect, investigate, respond—and map a tool chain as a pipeline, prioritizing interfaces over brochures.
Describe how a siem ingests events, normalizes data, indexes, evaluates rules, and presents dashboards; clarify it is not a detector, not a compliance certificate, and not a replacement for telemetry.
Understand how an endpoint agent watches process creation and parent processes, file changes, and network connections, decides on the host versus backend, and enables containment.
Design a simple enrichment playbook that enriches one alert with three lookups, records a full case history in dry run and real mode, and embraces enrichment not containment.
Understand what this course can and cannot show about open source versus commercial security tooling, and learn six essential vendor questions to separate transferable skills from non-transferables.
Learn to read a tool's documentation like an engineer by following six deliberate passes: data model, configuration precedence, release notes, limits, version reality check, and distinguishing specifications from local conventions.
Learn ten container commands for security tooling: pull and pin tags, start services, inspect logs, exec inside, and network containers on a private network by name before tearing down.
Generate safe, contained, repeatable attack traffic from a bench file with a fixed list of requests, proving containment before firing and producing verifiable receipts in logs and the store.
Explore tearing down and rebuilding lab environments at four depths, preserve state in volumes and files, and use snapshots and a build file to manage the bench.
State the one rule: only test on systems you own or with explicit written permission, keep the lab isolated from real networks, and use safe stand-ins with clear documentation.
Turn on auditd and journald on a real Linux machine, configure the Wazuh decoder to convert raw telemetry into named fields, and verify arrival and counting in the store.
Write and validate a Sysmin configuration to parse Windows event records on Linux, then create a custom rule for process creation and test negatives.
Write a Wazuh decoder and rule for a custom log, test it with the tester against good and broken lines, and validate field extraction in the live pipeline.
Describe how the Open Cybersecurity Schema Framework organizes events into categories and classes, uses identifying attributes and numeric identifiers for cross-vendor mapping and reliable definitions.
Export evidence with provenance by bundling rows, the query, and the window. Verify the bundle has not changed since written using a manifest and checksums, and rerun the store.
Tune noisy rules by measuring what triggers alerts, narrow matches to what you mean, and hold alert rate with threshold files while ensuring traffic is still recorded.
Learn how Zeek uses protocol logs instead of alerts and connects records via a connection identifier. Decide what to keep with health logs and volume, balancing recorder and detector roles.
Master sigma correlation rules to detect detections that cannot be written as a single event, choose among seven correlation types, define five attributes, use aliases, and set a time window.
Learn to build a two-rule correlation that groups events by host, enforces step order within a 15-minute window, and detects multi-step attacks even when the backend cannot correlate.
Clarify what a threat intelligence feed delivers using STIX indicators and expiry decisions at ingest. Explore how collections, Taxii, and decay mechanics shape reliable, time-bound indicators in security tooling.
This course contains the use of artificial intelligence.
This is a hands-on rebuild of the Cybersecurity Tools Bootcamp. Instead of touring dozens of products from the outside, you build one working security stack, called the bench, in Section 2 and keep operating it for the rest of the course. Every tool is installed, configured and exercised on screen, with real commands and real output. More than a hundred lectures are screen-recorded labs marked [LAB].
The course follows the order a security team actually works in. You start with telemetry: deciding what to collect, shipping Linux, Windows, application and network logs into a SIEM, and normalising them to a common schema so events become comparable. You then move into the SIEM core: indexing, searching, pivoting and exporting evidence that survives review. Network telemetry follows with Suricata and Zeek on the wire, then detection engineering with Sigma, correlation, enrichment and threat intelligence, and dashboards and alerting that cut noise rather than add to it.
On the endpoint side you learn what an EDR agent really does on a host and then build the open-source equivalent with the Wazuh agent and osquery: file integrity monitoring, persistence and credential-access detection, living-off-the-land detection and automated containment. Velociraptor gives you live forensics and hunting across the fleet, and case management brings alerts into a real analyst workflow with templates, timelines and reports.
Automation comes last, on purpose. You learn when a playbook is worth building, then build six real ones in Shuffle: phishing triage, alert enrichment, fleet queries, containment with human approval, automatic case creation and a daily detection-health report. Three DevSecOps sections put gates into a pipeline you are allowed to break: secret scanning with Gitleaks, static analysis with Semgrep, infrastructure-as-code scanning, SBOMs, signing and provenance with cosign, container and Kubernetes hardening, runtime detection with Falco and DAST with OWASP ZAP.
The final sections show the compliance pressure behind the tooling, how to measure detection coverage and programme health, and a capstone that chases a single incident end to end through the whole bench. Commercial EDR and SOAR consoles are discussed as concepts only; every lab runs on open-source tools you can install yourself.
Twelve downloadable working documents accompany the course, from the bench build log to the pipeline gate charter, so the artefacts you produce are ones you can reuse at work.