
TRAINING / AIDE
- Defensive security
- Intermediate
AI-Enhanced Detection Engineering.
Use Python, security data, and machine learning to build and evaluate detections. Learn where models help and how to examine their results.
- Duration
- 5 days
- Level
- Intermediate
- Delivery
- In-person / Remote
- Completion
- Accredible certificate
Security data & machine learning
Course overview.
AI-Enhanced Detection Engineering introduces data science within the detection engineering workflow. Security practitioners use Python and notebooks to prepare data, express detection logic, and evaluate machine learning results.
The curriculum includes Sigma rules, version control and validation concepts, pandas, scikit-learn, structured threat intelligence with STIX, and file features for malware classification. Exercises focus on understanding the data and interpreting model behavior. Teams examine where statistical methods can support an investigation and where their results need further scrutiny.
Who it is for
- Security analysts and detection engineers
- Software engineers working with security data
- Data practitioners supporting security operations
Tools and concepts
- Python and Jupyter
- pandas
- scikit-learn
- Sigma
- STIX
- Portable Executable file analysis
Learning outcomes
What your team will practice.
Use Python and notebooks to explore a security analysis problem.
Express detection logic and review how rules are managed and validated.
Prepare security data for analysis and evaluate its quality.
Train and evaluate models for security use cases.
Work with structured threat intelligence as an input to security analysis.
Extract file characteristics and evaluate their use in malware classification.
Curriculum
Inside the course.
Topics covered across five days of instructor-led training.
01Python and the analysis workflow
Use Python and notebooks to explore a security analysis problem.
- Python and Jupyter introduction
- Detection engineering workflow
- Data science project lifecycle
02Detection rules as code
Express detection logic and review how rules are managed and validated.
- Sigma rules
- Version control
- Continuous integration for rule validation
03Security data preparation
Prepare security data for analysis and evaluate its quality.
- pandas DataFrames
- Cleaning and normalization
- Exploratory analysis
04Machine learning and evaluation
Train and evaluate models for security use cases.
- scikit-learn
- Supervised and unsupervised learning
- Interpreting model results
05Structured threat intelligence
Work with structured threat intelligence as an input to security analysis.
- STIX concepts
- Structured security data
- Threat intelligence analysis exercises
06Malware features and classification
Extract file characteristics and evaluate their use in malware classification.
- Portable Executable file structure
- Static analysis features
- Classification and evaluation
Preparation
Before your team attends.
Prerequisites
- Familiarity with security events and detection use cases.
- Basic command-line skills; Python and Jupyter are introduced in the course.
What to bring
- A laptop, charger, and a modern web browser.
- Internet access suitable for connecting to the training environment.
What is included
- Instructor-led demonstrations and guided lab exercises.
- Course reference materials.
- An Accredible certificate of completion.
Workforce alignment
NICE Framework alignment.
Course objectives align with selected parts of the NICE Framework, version 2.2.0. This is a curriculum alignment, not full work-role qualification or NIST endorsement.
- Data AnalysisIO-WRL-001
- Defensive CybersecurityPD-WRL-001
View curriculum alignment
NICE alignment covers data analysis and defensive objectives. Use of machine learning does not imply coverage of the full AI Security competency area.
Python and the analysis workflow
Use Python and notebooks to explore a security analysis problem.
Related work roles: Data Analysis (IO-WRL-001)
- tasks
No separate task claimed.
- knowledge
- K0695Knowledge of programming principles and practices
- K1033Knowledge of scripting principles and practices
- K1344Knowledge of data science principles and practices
- skills
- S0597Skill in writing code in a currently supported programming language
Introductory notebook work supports programming and data-science foundations; no end-to-end software-development task is claimed.
Detection rules as code
Express detection logic and review how rules are managed and validated.
Related work roles: Defensive Cybersecurity (PD-WRL-001)
- tasks
- T1073Perform code reviews
- knowledge
- K1157Knowledge of enterprise-wide version control systems
- K1370Knowledge of continuous integration processes and procedures
- skills
- S0566Skill in developing signatures
- S0972Skill in performing code reviews
Writing and reviewing detection rules supports signature construction and code review.
Security data preparation
Prepare security data for analysis and evaluate its quality.
Related work roles: Data Analysis (IO-WRL-001)
- tasks
No separate task claimed.
- knowledge
- K1096Knowledge of data analysis tools and techniques
- K1344Knowledge of data science principles and practices
- skills
- S0726Skill in performing data normalization
- S0712Skill in evaluating data source quality
- S0854Skill in performing data analysis
Data preparation aligns with normalization, quality evaluation, and analysis skills rather than an inferred production data-engineering task.
Machine learning and evaluation
Train and evaluate models for security use cases.
Related work roles: Data Analysis (IO-WRL-001)
- tasks
No separate task claimed.
- knowledge
- K0904Knowledge of machine learning principles and practices
- skills
- S0955Skill in evaluating machine learning models
- S0646Skill in applying descriptive statistics
Model work aligns with machine-learning knowledge and evaluation skills; no separate hypothesis-testing task is claimed.
Structured threat intelligence
Work with structured threat intelligence as an input to security analysis.
Related work roles: Data Analysis (IO-WRL-001); Defensive Cybersecurity (PD-WRL-001)
- tasks
No separate task claimed.
- knowledge
- K1096Knowledge of data analysis tools and techniques
- skills
- S0854Skill in performing data analysis
STIX work is mapped to analysis of structured data; no complete threat-intelligence production role is claimed.
Malware features and classification
Extract file characteristics and evaluate their use in malware classification.
Related work roles: Data Analysis (IO-WRL-001); Defensive Cybersecurity (PD-WRL-001)
- tasks
No separate task claimed.
- knowledge
- K0857Knowledge of malware analysis tools and techniques
- K0904Knowledge of machine learning principles and practices
- skills
- S0884Skill in performing static malware analysis
- S0955Skill in evaluating machine learning models
File-feature exercises support static analysis and model evaluation skills; no multi-tier malware-analysis task is claimed.
Bring AIDE to your team.
Tell us your team size, preferred dates, and delivery format. Include AIDE in your inquiry.
