Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Threat Detection and Security Engineering

Microsoft via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This advanced-level course focuses on the technical design of enterprise security operations, continuous testing, and data protection. You'll learn to architect robust continuous control monitoring processes and orchestrate red and purple team exercises to proactively validate enterprise defenses. You'll also design sophisticated SIEM detection rules mapped to the MITRE ATT&CK framework, orchestrate rapid incident-triage playbooks, and craft comprehensive enterprise-level incident response plans. You'll design end-to-end security architecture patterns to classify and protect sensitive data across the organization, and establish advanced AI-driven threat response strategies to improve incident metrics and overall operational efficiency. This course is for security engineers, SOC analysts, and security architects with familiarity with SOC workflows, the MITRE ATT&CK framework, and introductory experience with incident response or SIEM platform management. By the end of this course, you will be able to design security architecture patterns to automate continuous monitoring and protect sensitive data; engineer SIEM detection use cases and MITRE ATT&CK-aligned catalogs across critical log sources; orchestrate red and purple team exercises to validate detective and preventive controls; and develop incident response plans and AI-driven strategies to optimize SOC investigation timelines. You will also learn to build a portfolio that showcases strategic thinking, risk evaluation, and practice navigating high-stakes technical leadership interviews. This course works with tools like Microsoft Sentinel for SIEM and SOAR, and Microsoft Purview for data protection. Some Microsoft Sentinel and Purview capabilities require a paid license or eligible tenant.

Syllabus

  • Continuous Monitoring: Monitor Controls Continuously
    • The "secure" architecture you designed yesterday may be vulnerable today. Learn to implement continuous monitoring utilizing Microsoft Security Exposure Management to visualize and remediate emerging attack paths before they are exploited.
  • Continuous Monitoring: Run Red and Purple Teams
    • Don't wait for a real attacker to test your defenses. Learn to structure and orchestrate simulated endpoint attacks to empirically validate that your Microsoft Defender XDR configurations detect and correlate specific threat behaviors.
  • SIEM and Threat: Engineer SIEM Rules
    • A SIEM is only as good as its data and its rules. Learn to connect external data sources to Microsoft Sentinel and write Scheduled Analytics Rules using Kusto Query Language (KQL) that turn raw data into actionable incidents.
  • SIEM & Threat: Develop ATT&CK Detections
    • Maintain the health of your SOC. Learn to map rules to the MITRE ATT&CK matrix in Sentinel, and how to use Automation Rules to gracefully handle false positives without blinding the organization to real threats.
  • SOC and IR: Orchestrate SOC Playbooks
    • Manual incident triage is too slow to stop modern ransomware. Learn to leverage Microsoft Sentinel Playbooks (powered by Azure Logic Apps) to automate enrichment, notification, and containment actions.
  • SOC and IR: Craft Enterprise IR Plans
    • When automation fails, humans must act. Learn to utilize Advanced Hunting in Defender XDR for manual threat response, and how to formalize these actions into a comprehensive Enterprise Incident Response plan.
  • Security Patterns: Design Sec Patterns
    • Stop reinventing the wheel. Learn to leverage the Microsoft Cybersecurity Reference Architectures (MCRA) to design standardized, secure-by-default patterns for new organizational workloads.
  • Security Patterns: Security Tool Integration
    • Security tools must work together seamlessly. Learn how to evaluate and integrate tooling in Defender XDR to ensure Automated Investigation and Response (AIR) capabilities function correctly across the enterprise.
  • Security Patterns: Classify & Protect Data
    • Data is the ultimate target. Learn to utilize Microsoft Purview to establish default sensitivity labeling, set up Information Barriers, and deploy Data Loss Prevention (DLP) policies to stop exfiltration.
  • GenAI Module: GenAI for Threat Detection
    • AI is fundamentally altering both the speed of cyberattacks and the defenders' capabilities. In this module, you will evaluate the impact of AI-driven threats and define enterprise strategies utilizing tools like Microsoft Security Copilot to improve and measure triage, investigation, and incident response metrics within the SOC.
  • Project Module: Threat Detection Pattern
    • Synthesize your knowledge of SIEM rule engineering, automated SOC playbooks, and Purview data protection to design a cohesive Threat Detection Pattern. You will apply risk-informed design principles to document how detection and response capabilities should integrate to reduce the impact of a specific threat scenario.
  • Launching Your Architecture Career
    • Transitioning from an engineer to an architect requires a shift in how you present yourself. Learn to build a portfolio that showcases strategic thinking, risk evaluation, and practice navigating high-stakes technical leadership interviews.

Taught by

Microsoft

Reviews

Start your review of Threat Detection and Security Engineering

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.