
This hands-on workshop guides participants through the detection engineering lifecycle using real Windows telemetry, live attacks, and Elastic Cloud.
Live Training $25 - $150
Course Length: 4 Hours
Includes a Certificate of Completion
Next scheduled date: August 22nd, 2025 @ 11:00 AM EDT
Description
This hands-on workshop guides participants through the detection engineering lifecycle using real Windows telemetry, live attacks, and Elastic Cloud. You’ll configure Sysmon, simulate attacks using tools like Metasploit, and write custom detections based on real data. Whether you’re a SOC analyst or security engineer, this lab-focused session will help you move from raw telemetry to actionable detections
System Requirements
-
Student Requirements
- Internet Access
- Ability to create a free Elastic Cloud trial account (email is required).
- Basic comfort with navigating Windows and Linux systems
-
VM/Lab/Student information
- A system with a browser and solid internet connection
- The ability to register via MetaCTF. Attendees will have access to the course VM and Labs via the MetaCTF platform for the duration of the workshop.
Syllabus
-
Lab setup
-
Detection Engineering Lifecycle
-
Alert Disposition
-
Installing and configuring Sysmon
-
Attack Simulations using tools like Metasploit
-
Writing custom detections in Elastic
-
Detection Verification using Echo<Threat
FAQ
Detection Engineers
Threat Hunters
Incident Responders
About the Instructor

Hal Denton
Bio
Hal Denton is a Security Analyst specializing in detection engineering, DFIR, threat hunting and CTI. With experience covering several facets of IT and InfoSec for over 20 years, Hal is committed in making the Blue Team struggles more bearable and provide a gateway for the future generation of InfoSec professionals. Hal has a BS in Computer Forensics and Digital Investigations.
Register for Upcoming
-
Filter by Product Date
-
Filter by Product Instructor
-
Filter by Product Type
Workshop: Telemetry to Tactics: A Hands-On Detection Engineering Workshop with Hal Denton
Complete Package
Live Training Hal Denton
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Hal Denton
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Hal Denton
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Hal Denton
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Hal Denton
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Similar Courses
-
Multiple InstructorsLive
Workshop: Investigating M365 Business Email Compromise with Patterson Cake
View Course This product has multiple variants. The options may be chosen on the product page -
Multiple InstructorsLiveOD
Workshop: SOC Detection Engineering Crash Course with Hayden Covington
View Course This product has multiple variants. The options may be chosen on the product page -
Multiple InstructorsLive
Workshop: Practical IT Fundamentals with Zach Hill
View Course This product has multiple variants. The options may be chosen on the product page -
Multiple InstructorsLive
Workshop: Hands on Kerberos with Tim Medin
View Course