01 - Introduction to Logging & SIEM
In modern application security, **visibility is survival**. If an attacker breaches your system and you have no logs, you have no way to detect the in...
02 - Security Logging Standards
Unstructured text logs (e.g., `User admin logged in from 192.168.1.5 at 12:00 PM`) are notoriously difficult to parse, search, and write detection rul...
03 - Detection Engineering & Sigma Rules
Detection Engineering is the practice of identifying threats by writing rules that analyze log data. To avoid vendor lock-in (e.g., writing rules only...
04 - SOAR & Automated Response
Security Orchestration, Automation, and Response (SOAR) takes the manual effort out of incident response. When a SIEM (or Sigma rule) triggers an aler...
05 - Log Retention & Compliance
Storing logs securely and for the correct amount of time is not just a security best practice; it is a legal and regulatory requirement.
06 - Hands-on Lab: Logging, Detection, & Response
In this self-contained lab, we will build a vulnerable Flask application that logs authentication events in structured JSON (ECS format). We will then...
07 - References & Resources
Expand your knowledge on logging, SIEM, detection engineering, and automated response with these industry-standard resources.
Logging & SIEM Masterclass
Welcome to the **Logging & SIEM Masterclass**. This module covers the critical defensive capabilities of security logging, centralized monitoring, det...