<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=325921436538399&amp;ev=PageView&amp;noscript=1">
Skip to the main content.

Create an account on our custom learning platform, Foundry™, to access our free and premium content.

Create Free Account


New call-to-action





Waitlist Registration

The Why Behind the Course

This course emerged from the frustration with bloated Detection Engineering education, brimming with superfluous history and irrelevant content. Our mission is clear: to equip you with the knowledge required for instant contribution to a Detection Engineering team. No need for five courses, twenty books, or a multitude of blogs - we’ve got you covered.

NOTE - This course is under development. The amount of  units, quizzes, and labs subject to change! Anticipating end of Q2 to early Q3 release. Join the waitlist and stay tuned!

Course Description

Building off of Detection Engineering 100, we’ll introduce advanced concepts that are seen in matured programs, such as how to approach baselining an environment and dipping your toes into UBA with machine learning concepts.

We’ll also discuss how to manage a Detection Engineering program - while keeping track of your content metrics. This knowledge will not only complete your “schoolhouse” knowledge of Detection Engineering, but give you the capability to help stand up programs.

Learning Outcomes

  • Learn how to work with large datasets utilizing data science methods such as machine learning.

  • Create fluid documentation, processes, and methods to track success within a detection engineering program.


  • Threat Detection Engineering 100

  • Level Effect’s Cyber Defense Analyst Program

  • 2+ years of professional experience in technology, preferably Cybersecurity









Course Author

Name: Tallis Jordan of Team Ghost (LinkedIn)

Positions Held: Lead Incident Response, Threat Detection Engineer, Purple Team Engineer, and Senior Threat Hunter

Experience: SOC Prime (Detection Specialty), Nuspire (MSSP), Army (Federal), 2K (Internal Security)

Volunteer Work: Director of Operations @ VetSec




Course Features

Live Practical Exam

We offer a practical exam you won’t find elsewhere on this subject: practical application, full-cycle detection engineering, and machine learning.

Live presentation with grading from a professional.

Real Malware

We utilize real malware that utilizes techniques you will see in the wild to teach our concepts and not just CTF or canned scenarios. You'll also find custom malware on the exam made by the course authors that you won't find online - this ensures exam integrity.

Tools of the Trade

Dive into a vast array of powerful tools in this comprehensive course, with over 20+ tools at your disposal. From FLOSS and HxD to Hidra, Wireshark, tshark, pySigma, Zeek, PEStudio, INetSim, RegShot, x64dbg, Caldera, and C2 Frameworks, and more

Experienced Authors

Our authors boast a combined experience of over 4.5 years in distinguished roles within the realm of senior detection engineering, and certifications on top. This isn't a theory course to memorize and then forget - it has been exclusively crafted by and for professionals in the field of detection engineering.

Cyber Range

Experience the power of a fully equipped cyber range, right at your fingertips. Accessible through any browser, our private cyber range offers a curated selection of cutting-edge machines, including REMnux, FLARE, Kali, an Analyst Workstation, ELK, and even a small enterprise network. 

Exclusive Access

Gain exclusive access to a private Discord community as well as repository packed with cutting-edge detection logic crafted by both students and instructors. Join forces with a talented and vibrant community to collaborate and enhance your skills long after the course concludes.

Explore the Curriculum

Learning Modules

Develop the skills for cybersecurity threat detection and analysis over 5 modules, learning how to create sophisticated detection strategies for a wide range of cyber threats, both in network traffic and endpoint security. 

Detection Engineer 2 (DE2) Exam

  • Prerequisites: completion of Detection Engineering 100 and associated labs OR 2+ year(s) of experience in a threat role (Threat Hunter, Threat Detection Engineering)

  • You will receive a scenario and randomly selected malware sample at the beginning of this phase (within your VM range). You will find the sample, perform the entire process of detection engineering in the range - including all documentation (including an evaluation guideline to track success), and show your work to the course instructor over a live call in a presentable format.

  • A week-long period of time for you to complete your work, and your live presentation will be scheduled within the next 30 days (24 hours of range time).

  • You will receive feedback within 72 hours from the instructor.

DE1 Badge _ Resized



His technical expertise in Cybersecurity and professionalism has provided me with a role model. His mentorship has helped me achieve my goals of making it into the industry - saving me enormous amounts of time with his guidance.
Travis S.
SOC Analyst
Tallis embodies the pinnacle of mentorship and leadership. He has guided me and pushed me to new heights; his confidence in me ignited a flame of pursuit towards achievement I never knew I possessed.
Brendan B.
Software Engineer
He has exposed me to an arsenal of skills and tools, guiding me through learning exploit development and reverse engineering. He doesn't hesitate to jump in and help when you get stuck either, no matter what it is.
Patrick W.
Threat Hunter
He readily shares his expertise, benefiting not only me, but everyone around him. I'm grateful for the opportunity to learn from him and value his organic guidance in order to advance my career.
Richard C.
Student of Cybersecurity

Cost of Attendance

The course will have multiple purchasing tiers. These tiers will meet the different needs of each student (i.e. course purchase with exam attempt, etc) and will soon be listed on the course page. You can expect a price range from $300-500.

We are also working on getting regional pricing so that it is affordable to the rate of your residence/citizenship. More details on this coming later!


Frequently Asked Questions

Do you what have it takes to detect the threats?

Waitlist Registration