← Every path

H2-CTDE · Core certification path

Runtime Detection and Response

H2 Certified Threat Detection Engineer

See what a workload actually does at runtime and act on it. eBPF detection in the kernel, network visibility, detections written as code and streamed through Kafka to a SIEM, alerting that reaches a human, and the incident response that follows.

5 courses · 19 lessons · ~33 h of guided work

Assumes Foundation

What you leave with

Tetragon policies watching syscalls, Hubble on the network, Sigma detections streamed through Kafka into a SIEM on Loki and VictoriaMetrics, alerts in chat, and an incident you ran end to end.

Runtime
Tetragon (eBPF)
Network
Hubble
Detections
Sigma
Pipeline
Kafka
SIEM
Loki + VictoriaMetrics
Alerting
Grafana / chat

Syllabus

5 courses · every lesson graded · minutes are guided work

  1. Course 01

    Kernel-level detection with eBPF

    Watch process execution, file access and network activity from inside the kernel with Tetragon, and tune out the false positives that make a policy useless.

    4 lessons · ~7 h

    1. 01What eBPF seesSyscalls, file access, network, from the kernel; why runtime beats log-only.90 min
    2. 02Writing a TracingPolicykprobe hooks on the syscalls that matter; a policy in git, deployed by GitOps.120 min
    3. 03Tuning false positivesThe MPTCP-autoload false positive from a Go scanner, reproduced and excluded; NotEqual not NotIn.120 min
    4. 04EnforcementFrom observe to block; killing a process on a policy match, and when not to.90 min

    Course checkWrite a policy that catches a described malicious behavior and does not fire on a named benign one; the grader runs both.

    You leave withTetragon TracingPolicies with kprobe hooks catching real behaviors, tuned to exclude the benign cases that flood a naive policy.

  2. Course 02

    Network visibility

    Every flow, identity-aware, so lateral movement shows up as a flow that should not exist. Hubble as the record and the alarm.

    3 lessons · ~5 h

    1. 01Flows as evidenceIdentity-aware flow logs; the flow that should not exist as a detection.90 min
    2. 02Hubble in depthLive flow visibility, service maps, and DNS visibility for exfiltration over DNS.120 min
    3. 03Lateral movementWhat it looks like in flows; a detection and the policy that prevents it.90 min

    Course checkFrom flow data, detect a simulated lateral-movement attempt and write the policy that would have stopped it.

    You leave withHubble capturing identity-aware flows, a detection for an unexpected flow, and the network policy that closes it.

  3. Course 03

    Detection engineering

    Turn a hypothesis about attacker behavior into a tested, version-controlled detection with a known false-positive rate, mapped to ATT&CK.

    4 lessons · ~7 h

    1. 01From hypothesis to detectionAn attacker behavior turned into a precise, testable rule.90 min
    2. 02SigmaPortable detections in Sigma; the same rule against two backends.120 min
    3. 03Precision and recallTuning a detection to a false-positive budget; the cost of getting it wrong either way.90 min
    4. 04Mapping to ATT&CKCoverage as a grid; the gaps that decide what you write next.90 min

    Course checkWrite three Sigma detections for given techniques, tune each to a false-positive budget, and map them to ATT&CK.

    You leave withA set of Sigma detections in git, each tested against benign and malicious samples, each mapped to an ATT&CK technique.

  4. Course 04

    The detection pipeline and SIEM

    Get events from everywhere to one place at scale: Tetragon and Hubble and app logs streamed through Kafka into a SIEM you built, not one you rent.

    4 lessons · ~7 h

    1. 01Events at scaleWhy the bus: Tetragon, Hubble and app logs through Kafka instead of point-to-point.120 min
    2. 02The SIEMLoki and VictoriaMetrics as the store; retention, tenancy, and the query that answers a hunt.120 min
    3. 03EnrichmentJoining events to identity and asset context so an alert carries its own explanation.90 min
    4. 04Threat intelligence feedsIngesting indicators and matching them against the stream, without drowning in noise.90 min

    Course checkBuild a pipeline that ingests three event sources through Kafka into the SIEM and answers a hunt query across all of them.

    You leave withA detection pipeline streaming runtime, network and application events through Kafka into Loki and VictoriaMetrics, with a hunt query that spans them.

  5. Course 05

    Alerting and incident response

    An alert that reaches a human with the context to act, an on-call that is humane, and an incident run to a clean forensic timeline.

    4 lessons · ~7 h

    1. 01Alerting to a humanThresholds you justified, routing to chat, and a runbook link that resolves; alert rules that fire for real reasons.90 min
    2. 02On-call that is humaneRotation, escalation, and alert fatigue as a design problem.90 min
    3. 03Incident responseDetect, contain, eradicate, recover; roles and the first five minutes.120 min
    4. 04Forensics and the timelinePreserving evidence and reconstructing what happened, in order, from your own telemetry.120 min

    Course checkGiven a firing alert, run the incident to containment and produce a timeline that would survive a review.

    You leave withAlerts routed to chat with runbook links, an on-call rotation and escalation, and a forensic timeline you produced from a simulated incident.

Certification course

H2 Certified Threat Detection Engineer

$499 · one price · courses + 90-day labs + exam

A live intrusion across your stack: initial access, privilege escalation, lateral movement and exfiltration. Detect each stage, contain it, and produce a forensic timeline from your own telemetry.

Opens when Foundation is complete and the 5 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.

Create an account to enrol