Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Cybersecurity Tools Bootcamp 2026: SIEM, EDR, SOAR+DevSecOps
Rating: 2.9 out of 5(5 ratings)
123 students

Cybersecurity Tools Bootcamp 2026: SIEM, EDR, SOAR+DevSecOps

Build and run a real open-source SIEM, EDR, SOAR and DevSecOps bench: Wazuh, Suricata, Sigma, Velociraptor, Shuffle
Created byNEXUS ACADEMY
Last updated 9/2026
English
English [Auto],

What you'll learn

  • Build and operate a complete open-source detection and response stack (Wazuh, OpenSearch, Suricata, Zeek, osquery, Velociraptor, Shuffle) on one machine
  • Decide what telemetry to collect, ship Linux, Windows, application and network logs into a SIEM and normalise them to a common schema
  • Write, test and version detection rules with Sigma, map them to MITRE ATT&CK and cut false positives with measured evidence
  • Detect persistence, credential access and living-off-the-land activity on endpoints, then contain and investigate hosts with live forensics
  • Put security gates into a CI pipeline: secret scanning, SAST, IaC scanning, SBOM and signing, container and Kubernetes hardening, runtime detection
  • Design and build SOAR playbooks that enrich, query, contain with human approval and open cases automatically
  • Prove the programme works with coverage maps, time metrics and audit-ready evidence exports

Course content

21 sections • 298 lectures • 28h 39m total length
  • Course Documents and How to Use Them6:21
  • Section 1 Intro: The Map Before the Tools3:05

    Place security tools into the four jobs—collect, detect, investigate, respond—and map a tool chain as a pipeline, prioritizing interfaces over brochures.

  • What a Security Tool Chain Actually Is4:49
  • [LAB] One Event, Six Stations: Following a Single Log Line7:17
  • The Four Job Families: Collect, Detect, Investigate, Respond4:50
  • SIEM in One Lecture: What It Is and What It Is Not4:48

    Describe how a siem ingests events, normalizes data, indexes, evaluates rules, and presents dashboards; clarify it is not a detector, not a compliance certificate, and not a replacement for telemetry.

  • [LAB] Ingest, Index, Search: Standing Up a Live Store7:58
  • EDR in One Lecture: Agents, Telemetry and Containment5:01

    Understand how an endpoint agent watches process creation and parent processes, file changes, and network connections, decides on the host versus backend, and enables containment.

  • [LAB] Endpoint Telemetry Without a Vendor: osquery on a Live Host6:49
  • SOAR in One Lecture: Playbooks, Not Magic4:56
  • [LAB] The Simplest Honest Playbook: Enrichment, Not Containment6:41

    Design a simple enrichment playbook that enriches one alert with three lookups, records a full case history in dry run and real mode, and embraces enrichment not containment.

  • DevSecOps in One Lecture: Moving the Gate, Not the Blame4:53
  • [LAB] A Gate That Actually Fails: Scanning an Image on Camera6:47
  • Where the Four Overlap and Where Teams Get It Wrong4:44
  • Open Source vs Commercial: What This Course Can and Cannot Show You4:38

    Understand what this course can and cannot show about open source versus commercial security tooling, and learn six essential vendor questions to separate transferable skills from non-transferables.

  • Reading a Tool's Documentation Like an Engineer4:54

    Learn to read a tool's documentation like an engineer by following six deliberate passes: data model, configuration precedence, release notes, limits, version reality check, and distinguishing specifications from local conventions.

  • [LAB] The Half-Hour Documentation Routine, On Camera7:08
  • How This Course Works: The Bench, the Labs, the Artefact4:29

Requirements

  • A computer that can run Docker with roughly 8 GB of RAM free for the lab stack; all tools used are free and open source
  • Basic Linux command-line comfort and general IT or networking knowledge; no prior SIEM, EDR or SOAR experience is required

Description

This course contains the use of artificial intelligence.


This is a hands-on rebuild of the Cybersecurity Tools Bootcamp. Instead of touring dozens of products from the outside, you build one working security stack, called the bench, in Section 2 and keep operating it for the rest of the course. Every tool is installed, configured and exercised on screen, with real commands and real output. More than a hundred lectures are screen-recorded labs marked [LAB].


The course follows the order a security team actually works in. You start with telemetry: deciding what to collect, shipping Linux, Windows, application and network logs into a SIEM, and normalising them to a common schema so events become comparable. You then move into the SIEM core: indexing, searching, pivoting and exporting evidence that survives review. Network telemetry follows with Suricata and Zeek on the wire, then detection engineering with Sigma, correlation, enrichment and threat intelligence, and dashboards and alerting that cut noise rather than add to it.


On the endpoint side you learn what an EDR agent really does on a host and then build the open-source equivalent with the Wazuh agent and osquery: file integrity monitoring, persistence and credential-access detection, living-off-the-land detection and automated containment. Velociraptor gives you live forensics and hunting across the fleet, and case management brings alerts into a real analyst workflow with templates, timelines and reports.


Automation comes last, on purpose. You learn when a playbook is worth building, then build six real ones in Shuffle: phishing triage, alert enrichment, fleet queries, containment with human approval, automatic case creation and a daily detection-health report. Three DevSecOps sections put gates into a pipeline you are allowed to break: secret scanning with Gitleaks, static analysis with Semgrep, infrastructure-as-code scanning, SBOMs, signing and provenance with cosign, container and Kubernetes hardening, runtime detection with Falco and DAST with OWASP ZAP.


The final sections show the compliance pressure behind the tooling, how to measure detection coverage and programme health, and a capstone that chases a single incident end to end through the whole bench. Commercial EDR and SOAR consoles are discussed as concepts only; every lab runs on open-source tools you can install yourself.


Twelve downloadable working documents accompany the course, from the bench build log to the pipeline gate charter, so the artefacts you produce are ones you can reuse at work.

Who this course is for:

  • Security analysts, SOC joiners and IT engineers who have read about SIEM, EDR, SOAR and DevSecOps but have never built or operated the stack
  • System administrators moving into security and developers being handed pipeline security who want hands-on, tool-by-tool practice