Blue-team operations path

SIEM and IDS/IPS Operations

Build, monitor and defend modern environments using security logs, detection engineering, network visibility and practical SOC workflows.

Learn how to collect and analyze events, deploy defensive network sensors, tune detections, investigate incidents and prepare tested configurations for controlled production use.

Intermediate10-Hour Core Path30 Guided Lessons 4 Practical ModulesDefensive SecuritySOC Operations
CategorySIEM & IDS/IPS
Learning modesBeginner · Intermediate · Advanced
Core duration10 hours
AccessPublic course
Course mission

Operate the complete defensive signal path

Move from raw security telemetry to validated alerts, evidence-led investigations and controlled production readiness.

01

Collect

Onboard Windows, Linux, syslog, endpoint and network telemetry with known ownership and time quality.

02

Detect

Normalize fields, build testable rules, tune noise and validate that each detection supports a clear objective.

03

Investigate

Correlate endpoint events, Suricata alerts and Zeek metadata into a defensible analyst timeline.

04

Operationalize

Prepare change control, rollback, health monitoring, reporting and audit-ready documentation.

Recommended lab

Isolated monitoring architecture

Use systems you own, local virtual machines, approved sample logs and intentionally generated test events. Product sizing varies with retention, traffic volume and enabled services.

Complete curriculum

30 guided lessons across 4 modules

Select a learning mode, search the course, and open any lesson. Content changes instantly without reloading.

Course progress 0%
0 of 30 lessons complete
Learning mode
Cross-platform operations

Equivalent defensive workflows

Terminology differs by platform. The operational objective remains consistent: collect trusted data, search it, create a validated detection and manage the resulting investigation.

OperationWazuhElastic SecurityMicrosoft SentinelSplunk ES 8.4
Search logsDashboard search / index queryDiscover with KQL, ES|QL or applicable queryKQL across workspace or data-lake contextSPL
Create detectionCustom decoder and ruleDetection ruleAnalytics ruleDetection / correlation search
Manage investigationAlert workflow and integrationsAlerts, Timeline and CasesAlerts and incidentsFindings, finding groups and investigations
Endpoint collectionWazuh AgentFleet-managed Elastic AgentData connectors and supported agentsUniversal Forwarder or supported integrations
Capstone

Defensive monitoring final project

Design, validate and document a small authorized monitoring environment that connects endpoint telemetry with network evidence.

References and further learning

Official product documentation

Commands and terminology in this course were checked against these primary sources. Always re-check the linked release documentation before changing a lab or production environment.

Instructions requiring final version confirmation

Windows agent package links, Elastic enrollment commands, Snort build dependencies, Security Onion installation choices, cloud connector menus, and licensed-platform screens are generated per tenant or release. The course therefore directs learners to the product’s current in-product command or official release guide instead of freezing fragile values.

Final examination

25 questions · 70% pass mark

Question 1 of 25