К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Threat Detection and Security Engineering · LearnSpace
Назад в каталог
courseraIT и технологии

Threat Detection and Security Engineering

Курс от Microsoft
Продвинутый≈ 9.7 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

This advanced-level course focuses on the technical design of enterprise security operations, continuous testing, and data protection. You'll learn to architect robust continuous control monitoring processes and orchestrate red and purple team exercises to proactively validate enterprise defenses. You'll also design sophisticated SIEM detection rules mapped to the MITRE ATT&CK framework, orchestrate rapid incident-triage playbooks, and craft comprehensive enterprise-level incident response plans. You'll design end-to-end security architecture patterns to classify and protect sensitive data across the organization, and establish advanced AI-driven threat response strategies to improve incident metrics and overall operational efficiency. This course is for security engineers, SOC analysts, and security architects with familiarity with SOC workflows, the MITRE ATT&CK framework, and introductory experience with incident response or SIEM platform management. By the end of this course, you will be able to design security architecture patterns to automate continuous monitoring and protect sensitive data; engineer SIEM detection use cases and MITRE ATT&CK-aligned catalogs across critical log sources; orchestrate red and purple team exercises to validate detective and preventive controls; and develop incident response plans and AI-driven strategies to optimize SOC investigation timelines. You will also learn to build a portfolio that showcases strategic thinking, risk evaluation, and practice navigating high-stakes technical leadership interviews. This course works with tools like Microsoft Sentinel for SIEM and SOAR, and Microsoft Purview for data protection. Some Microsoft Sentinel and Purview capabilities require a paid license or eligible tenant.

Навыки, которые вы освоите

Threat DetectionData Loss PreventionSecurity Information and Event Management (SIEM)MITRE ATT&CK FrameworkSecurity ControlsEndpoint Detection and ResponseContinuous MonitoringIncident ResponseSecurity EngineeringEnterprise ArchitectureCyber Threat HuntingSecurity ManagementData SecurityIncident ManagementCloud SecurityEncryptionIT Security ArchitectureEndpoint SecurityAI SecurityComputer Security Incident Management

Программа курса

12 модулей · 64 учебных материалов

01Continuous Monitoring: Monitor Controls Continuously5 материалов
The Illusion of Point-in-Time ComplianceЧтениеManaging Exposure and Attack PathsВидеоReviewing Attack PathsЧтениеIdentify TechHealth's Weakest LinkЛабораторная

Учитесь у экспертов

Microsoft

Преподаватель курса

Threat Detection and Security Engineering
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 9.7 ч

12 модулей

Язык: Английский

Часть программы вашего университета
Knowledge Check: Continuous MonitoringЗадание
02Continuous Monitoring: Run Red and Purple Teams6 материалов
Silent Failures in the SOCDIALOGUEBreach and Attack Simulation (BAS) ConceptsЧтениеReviewing Simulation OutcomesЧтениеHands-on Activity: Evaluate a Purple Team ExerciseЗаданиеKnowledge Check: Security TestingЗаданиеGraded Quiz: Continuous Monitoring and TestingЗадание
03SIEM and Threat: Engineer SIEM Rules5 материалов
The Danger of Alert FatigueВидеоSentinel Data Connectors and Analytics RulesЧтениеCreating Scheduled Analytics RulesЧтениеArchitect a TechHealth DetectionЛабораторнаяKnowledge Check: SIEM EngineeringЗадание
04SIEM & Threat: Develop ATT&CK Detections6 материалов
The Importance of a Tuning LifecycleВидеоHandling False Positives with Automation RulesЧтениеSuppressing Benign AlertsЧтениеTune the TechHealth SOCЛабораторнаяKnowledge Check: Tuning and FrameworksЗаданиеGraded Quiz: SIEM and Threat DetectionsЗадание
05SOC and IR: Orchestrate SOC Playbooks5 материалов
The Need for Machine-Speed ResponseDIALOGUESentinel Playbooks and Logic AppsЧтениеCustomizing a Playbook TemplateЧтениеArchitect an Automated Triage FlowЛабораторнаяKnowledge Check: Playbook OrchestrationЗадание
06SOC and IR: Craft Enterprise IR Plans6 материалов
Crisis Management in the War RoomЧтениеIntegrated XDR Response and Advanced HuntingВидеоTaking Action via Advanced HuntingЧтениеHunt and Contain a ThreatЛабораторнаяKnowledge Check: IR Plans and HuntingЗаданиеGraded Quiz: SOC and Incident ResponseЗадание
07Security Patterns: Design Sec Patterns5 материалов
The Danger of Architectural Technical DebtВидеоThe Microsoft Cybersecurity Reference Architectures (MCRA)ЧтениеNavigating MCRA DiagramsЧтениеMap a New TechHealth WorkloadЛабораторнаяKnowledge Check: Security Patterns & MCRAЗадание
08Security Patterns: Security Tool Integration5 материалов
The Problem with Siloed Security ToolsВидеоDefender XDR and Automated InvestigationЧтениеConfiguring AIR CapabilitiesЧтениеReview an AIR InvestigationЛабораторнаяKnowledge Check: Tool Integration & AIRЗадание
09Security Patterns: Classify & Protect Data6 материалов
Data is the Ultimate TargetDIALOGUEPurview DLP and Sensitivity LabelsЧтениеCreating a Default Sensitivity Label in Microsoft PurviewЧтениеArchitect a TechHealth DLP PolicyЛабораторнаяKnowledge Check: Data ProtectionЗаданиеGraded Quiz: Security Patterns and Data ProtectionЗадание
10GenAI Module: GenAI for Threat Detection5 материалов
The AI Arms Race in CybersecurityЧтениеMicrosoft Security Copilot Use CasesВидеоPrompting for Incident ContextЧтениеHands-on Activity: Draft an AI SOC StrategyЗаданиеKnowledge Check: GenAI for Threat DetectionЗадание
11Project Module: Threat Detection Pattern4 материалов
Why This Project MattersЧтениеProject Requirements: Data Protection, Detection Rules, and Response WorkflowЧтениеProject Instructions: Building the Threat Detection Control MatrixЧтениеDesign a Threat Detection PatternЗадание
12Launching Your Architecture Career6 материалов
The Mindset of a Security ArchitectВидеоArchitecting Your Resume and PortfolioЧтениеNavigating the Leadership InterviewВидеоHands-on Activity: Polish Your Architecture PortfolioЗаданиеKnowledge Check: Career StrategiesЗаданиеGraded Quiz: Advancing in Cybersecurity ArchitectureЗадание