A complete, vendor-independent course covering everything an analyst and architect needs: Splunk SPL, MITRE ATT&CK, Sigma detection engineering, threat hunting, incident response, cloud/hybrid monitoring, and AI in the modern SOC. Twelve modules, 31 lessons, 4 hands-on labs on free tools, 3 full case studies, and knowledge checks throughout.
12modules · 31 lessons
4hands-on labs, free tools only
3full incident case studies
$0lab tooling cost
Why this course
Vendor-independent by design — the concepts transfer across Splunk, Sentinel, QRadar, Elastic, and Wazuh, not just one product.
⌘
Hands-on, not theory-only
4 labs run on real, free tooling — Wazuh, Splunk Free, ATT&CK Navigator, Atomic Red Team — deployed on your own machine.
⇄
Analyst to architect
Starts at SOC fundamentals, ends at capacity planning, multi-tenant SIEM design, and a full capstone architecture exercise.
◎
Grounded in 2026 practice
Covers Sigma detection engineering, risk-based alerting, and where AI genuinely helps (and doesn't) in a modern SOC.
What You'll Actually Achieve
Concrete outcomes, not vague promises — visible here in the free preview before you decide.
📚 Learning Outcomes
Deploy and operate a real SIEM (Wazuh) from scratch, not just interpret pre-built dashboards
Write a detection query in SPL that goes from data exploration to a scheduled, working alert
Build an honest ATT&CK coverage heatmap and use it to justify what to build next, not just to look thorough
Author, convert, and productionize a Sigma rule — the actual detection engineering loop end to end
🔬 Lab Outcomes — What You'll Actually Build
A live Wazuh SIEM instance you deployed and configured yourself, reused across three connected missions
A working, scheduled Splunk correlation search for brute-force detection
A Sigma rule you wrote, converted, and validated against real generated telemetry
A documented Atomic Red Team simulation you hunted for manually — and either found or learned from missing
Industry Relevance — JobTkl's Assessment
Our own rubric based on tool currency, real-world grounding, and current hiring signal — not a third-party certification or independently verified score.
Tool/Framework CurrencyWazuh, Splunk, Sigma, ATT&CK Navigator, Atomic Red Team — the real toolchain SOC teams use today
Real-World GroundingOne continuous SIEM instance reused across the whole course — matches how a real detection program actually operates
Current Hiring DemandDetection engineering and threat hunting are consistently named among the highest-demand SOC skills in current hiring data
Curriculum
Module 1 is free. The rest unlock with a subscription.
One course. One price.
Lifetime access to all 12 modules and future updates.