SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis poster provides a practical, end-to-end view of Detection Engineering, guiding defenders from raw log data to meaningful alerts.
Built around the Detection Engineering Life Cycle, it breaks down how detections are identified, developed, tested, deployed, and continuously improved, while also covering key concepts like data collection strategies, SIEM architecture considerations, and common detection techniques. Designed as a quick-reference visual, it helps analysts, engineers, and SOC teams better understand how to turn data into reliable, actionable detections grounded in real-world practices from SEC555: Detection Engineering and SIEM Analytics.


Kathryn Hedley has led various forensic teams since 2010, spending three years embedded within a cross-organizational team, liaising directly with multiple clients. She is currently a Director and Digital Forensic Specialist for Khyrenz Ltd.
Learn more

Nick Mitropoulos is a SANS Certified Instructor and author of SEC555: Detection Engineering and SIEM Analytics. As CEO of Scarlet Dragonfly and a veteran of SOC and incident response leadership, he equips students with real-world skills in detection engineering. Nick also serves on the GIAC Advisory Board, SANS CISO Network, and faculty of the SANS Technology Institute.
Learn more
















