TRAINING COURSES

Adversary Tactics: Detection

iAPM-HeroImage@2x-2_7f1140
APM-MainImage-ATD@2x

WHAT TO EXPECT

Build detections that focus on how attackers operate

Many organizations struggle with the same detection challenges: expensive toolsets generating oceans of alerts, overwhelmed analysts, and ineffective response to real threats. The problem isn’t lack of tools—it’s lack of strategy.

This course teaches how to proactively search for advanced threat actors and close the gap from infection to detection. Participants go beyond brittle indicators and develop detection engineering capabilities for adversary behaviors and TTPs that work no matter what security toolset is deployed, creating sustainable detection programs that shift the advantage back to defenders.

key takeaways

Course summary

Building detections that hold up against sophisticated adversaries takes more than the right toolset.

You bought all the latest detection tools, but somehow still can’t seem to detect mimikatz. IT is screaming about resource consumption from multitudes of security tools on endpoints, analysts are barely staying afloat on the oceans of data your toolsets have created, and the latest red team report detailed another ineffective response. Sound familiar? In this course we’ll address detection engineering strategy and methodologies to build robust alerting that improves detection and response capabilities—from understanding the “why” to technical implementation. You will learn to apply these approaches regardless of the security toolsets deployed.

Participants will learn

Cards-Learn1@2x

How to shift from brittle IOC identification to threat-based detection focused on techniques

Icons-Alert

How to develop alerting and detection strategies and incorporate them into a security operations program

Icons-Connect

How to create robust detections based on attacker behavior rather than easily bypassed static indicators

A CLOSER LOOK AT THE COURSE

Adversary Tactics: Detection

Enterprise networks face constant attacks from adversaries of all skill levels. Blue teamers often feel they’re fighting a losing battle: attackers “only need to be successful once” while defenders must prevent every attack. This course flips that dynamic by shifting focus from prevention to detection. Rather than attempting to prevent every breach, assume compromise will occur and develop robust detections across all attack stages. By focusing on post-exploitation activity—privilege escalation, lateral movement, and persistence—you create a detection minefield where attackers “only need to be detected once” for defenders to respond effectively.

Dig into Detection

This course moves beyond signature-based alerting to focus on adversary Tactics, Techniques, and Procedures (TTPs). Participants learn to engineer detections based on attacker behavior rather than brittle indicators, using open-source tools like Sysmon, Windows Event Logs, and ELK to analyze host data at scale. In hands-on labs, participants create robust detections in a simulated enterprise network undergoing active compromise.

Carousel1-Detection@2x_42264c

Here’s what we’ll cover:

  • The SpecterOps Funnel of Fidelity
  • Threat Hunting Introduction
  • MITRE ATT&CK and Adversary TTPs
  • Interpreting Threat Intelligence
  • Data Pipelines
ATD-Day1@2x_3e6347

Here’s what we’ll cover:

  • Data Preparation
  • Data Documentation
  • Data Modeling
  • Data Standardization
  • Data Quality
  • BloodHound
  • Detection Engineering Methodology
ATD-Day2@2x_6fdade

Here’s what we’ll cover:

  • Detection Engineering Methodology (cont.)
  • Identity-Driven Detections
  • Alerting & Detection Strategy Framework
  • Triage
  • SOAR
  • Metrics
ATD-Day3@2x_c265cb

Here’s what we’ll cover:

  • Capstone Detection Exercise
  • Attack Scenario Breakdown
  • Detection Presentations & Feedback
ATD-Day4@2x_a1669c

Overview

Dig into Detection

This course moves beyond signature-based alerting to focus on adversary Tactics, Techniques, and Procedures (TTPs). Participants learn to engineer detections based on attacker behavior rather than brittle indicators, using open-source tools like Sysmon, Windows Event Logs, and ELK to analyze host data at scale. In hands-on labs, participants create robust detections in a simulated enterprise network undergoing active compromise.

Carousel1-Detection@2x_42264c

Day 1

Here’s what we’ll cover:

  • The SpecterOps Funnel of Fidelity
  • Threat Hunting Introduction
  • MITRE ATT&CK and Adversary TTPs
  • Interpreting Threat Intelligence
  • Data Pipelines
ATD-Day1@2x_3e6347

Day 2

Here’s what we’ll cover:

  • Data Preparation
  • Data Documentation
  • Data Modeling
  • Data Standardization
  • Data Quality
  • BloodHound
  • Detection Engineering Methodology
ATD-Day2@2x_6fdade

Day 3

Here’s what we’ll cover:

  • Detection Engineering Methodology (cont.)
  • Identity-Driven Detections
  • Alerting & Detection Strategy Framework
  • Triage
  • SOAR
  • Metrics
ATD-Day3@2x_c265cb

Day 4

Here’s what we’ll cover:

  • Capstone Detection Exercise
  • Attack Scenario Breakdown
  • Detection Presentations & Feedback
ATD-Day4@2x_a1669c

Before you attend

Who should attend

This class is intended for security analysts and blue teamers wanting to learn how to effectively build repeatable detections in enterprise networks. This course offers benefits to participants of most levels of security operations experience, from SOC analysts to experienced security defenders. Those with a strong technical background will have the opportunity for a deep dive into key concepts and labs. Participants in less technically focused positions will be exposed to a robust detection engineering framework that provides the building blocks to create highly effective detection strategies.

Prerequisites

Participants should have previous network detection and response experience and/or knowledge of offensive tools and techniques, primarily post-exploitation techniques. Additionally, familiarity with using a SIEM, such as ELK or Splunk, will be helpful.

What to bring

Participants will need a laptop with a modern web browser. All labs are completed through a training portal that contains a range with simulated enterprise networks under attack and defensive workstations from which participants will operate.

There are no local virtual machines or special software required to fully participate in the course or labs.

What you receive

During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.

Upon completion of the course, participants receive:

  • A copy of the course slides
  • A certificate of completion
  • A course challenge coin
  • A digital badge

Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.

MORE WAYS TO TRAIN

Private and custom training

SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.

5050-1-AttackPaths_b167b9

 DEEPEN YOUR TRADECRAFT

Explore additional training courses

TrainingPage-ActiveDirectory_9494c3

Adversary Perspectives: Active Directory

Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.

Learn More
TrainingPage-Azure

Adversary Perspectives: Azure

Discover how adversaries view, target, and exploit Azure and Entra ID environments.

Learn More
TrainingPage-RedTeam

Adversary Tactics: Red Team Operations

Go beyond Domain Admin and sharpen your offense-in-depth skills.

Learn More
TrainingPage-OffensiveTradecraft

Adversary Tactics: Identity-Driven Offensive Tradecraft

What turns a path into an attack path? Learn how to find and abuse them.

Learn More
TrainingPage-TradecraftAnalysis

Adversary Tactics: Tradecraft Analysis

Deconstruct how attack techniques really work, then build detections or learn how to evade them.

Learn More

SpecterOps Tradecraft Academy

Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.

TradeCraftAcademyLogo@2x_3266ac