TRAINING COURSES
Adversary Tactics: Detection
WHAT TO EXPECT
Build detections that focus on how attackers operate
Many organizations struggle with the same detection challenges: expensive toolsets generating oceans of alerts, overwhelmed analysts, and ineffective response to real threats. The problem isn’t lack of tools—it’s lack of strategy.
This course teaches how to proactively search for advanced threat actors and close the gap from infection to detection. Participants go beyond brittle indicators and develop detection engineering capabilities for adversary behaviors and TTPs that work no matter what security toolset is deployed, creating sustainable detection programs that shift the advantage back to defenders.
key takeaways
Course summary
Building detections that hold up against sophisticated adversaries takes more than the right toolset.
You bought all the latest detection tools, but somehow still can’t seem to detect mimikatz. IT is screaming about resource consumption from multitudes of security tools on endpoints, analysts are barely staying afloat on the oceans of data your toolsets have created, and the latest red team report detailed another ineffective response. Sound familiar? In this course we’ll address detection engineering strategy and methodologies to build robust alerting that improves detection and response capabilities—from understanding the “why” to technical implementation. You will learn to apply these approaches regardless of the security toolsets deployed.
Participants will learn
How to shift from brittle IOC identification to threat-based detection focused on techniques
How to develop alerting and detection strategies and incorporate them into a security operations program
How to create robust detections based on attacker behavior rather than easily bypassed static indicators
A CLOSER LOOK AT THE COURSE
Adversary Tactics: Detection
Enterprise networks face constant attacks from adversaries of all skill levels. Blue teamers often feel they’re fighting a losing battle: attackers “only need to be successful once” while defenders must prevent every attack. This course flips that dynamic by shifting focus from prevention to detection. Rather than attempting to prevent every breach, assume compromise will occur and develop robust detections across all attack stages. By focusing on post-exploitation activity—privilege escalation, lateral movement, and persistence—you create a detection minefield where attackers “only need to be detected once” for defenders to respond effectively.
Dig into Detection
This course moves beyond signature-based alerting to focus on adversary Tactics, Techniques, and Procedures (TTPs). Participants learn to engineer detections based on attacker behavior rather than brittle indicators, using open-source tools like Sysmon, Windows Event Logs, and ELK to analyze host data at scale. In hands-on labs, participants create robust detections in a simulated enterprise network undergoing active compromise.
Here’s what we’ll cover:
- The SpecterOps Funnel of Fidelity
- Threat Hunting Introduction
- MITRE ATT&CK and Adversary TTPs
- Interpreting Threat Intelligence
- Data Pipelines
Here’s what we’ll cover:
- Data Preparation
- Data Documentation
- Data Modeling
- Data Standardization
- Data Quality
- BloodHound
- Detection Engineering Methodology
Here’s what we’ll cover:
- Detection Engineering Methodology (cont.)
- Identity-Driven Detections
- Alerting & Detection Strategy Framework
- Triage
- SOAR
- Metrics
Here’s what we’ll cover:
- Capstone Detection Exercise
- Attack Scenario Breakdown
- Detection Presentations & Feedback
Before you attend
Who should attend
This class is intended for security analysts and blue teamers wanting to learn how to effectively build repeatable detections in enterprise networks. This course offers benefits to participants of most levels of security operations experience, from SOC analysts to experienced security defenders. Those with a strong technical background will have the opportunity for a deep dive into key concepts and labs. Participants in less technically focused positions will be exposed to a robust detection engineering framework that provides the building blocks to create highly effective detection strategies.
Prerequisites
Participants should have previous network detection and response experience and/or knowledge of offensive tools and techniques, primarily post-exploitation techniques. Additionally, familiarity with using a SIEM, such as ELK or Splunk, will be helpful.
What to bring
Participants will need a laptop with a modern web browser. All labs are completed through a training portal that contains a range with simulated enterprise networks under attack and defensive workstations from which participants will operate.
There are no local virtual machines or special software required to fully participate in the course or labs.
What you receive
During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.
Upon completion of the course, participants receive:
- A copy of the course slides
- A certificate of completion
- A course challenge coin
- A digital badge
Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.
MORE WAYS TO TRAIN
Private and custom training
SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.
DEEPEN YOUR TRADECRAFT
Explore additional training courses
Adversary Perspectives: Active Directory
Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.
Adversary Perspectives: Azure
Discover how adversaries view, target, and exploit Azure and Entra ID environments.
Adversary Tactics: Red Team Operations
Go beyond Domain Admin and sharpen your offense-in-depth skills.
Adversary Tactics: Identity-Driven Offensive Tradecraft
What turns a path into an attack path? Learn how to find and abuse them.
Adversary Tactics: Tradecraft Analysis
Deconstruct how attack techniques really work, then build detections or learn how to evade them.
SpecterOps Tradecraft Academy
Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.