H2-CTDE · Core certification path
Runtime Detection and Response
H2 Certified Threat Detection Engineer
See what a workload actually does at runtime and act on it. eBPF detection in the kernel, network visibility, detections written as code and streamed through Kafka to a SIEM, alerting that reaches a human, and the incident response that follows.
5 courses · 19 lessons · ~33 h of guided work
Assumes Foundation
What you leave with
Tetragon policies watching syscalls, Hubble on the network, Sigma detections streamed through Kafka into a SIEM on Loki and VictoriaMetrics, alerts in chat, and an incident you ran end to end.
- Runtime
- Tetragon (eBPF)
- Network
- Hubble
- Detections
- Sigma
- Pipeline
- Kafka
- SIEM
- Loki + VictoriaMetrics
- Alerting
- Grafana / chat
Syllabus
5 courses · every lesson graded · minutes are guided work
Course 01
Kernel-level detection with eBPF
Watch process execution, file access and network activity from inside the kernel with Tetragon, and tune out the false positives that make a policy useless.
4 lessons · ~7 h
- 01What eBPF seesSyscalls, file access, network, from the kernel; why runtime beats log-only.90 min
- 02Writing a TracingPolicykprobe hooks on the syscalls that matter; a policy in git, deployed by GitOps.120 min
- 03Tuning false positivesThe MPTCP-autoload false positive from a Go scanner, reproduced and excluded; NotEqual not NotIn.120 min
- 04EnforcementFrom observe to block; killing a process on a policy match, and when not to.90 min
Course checkWrite a policy that catches a described malicious behavior and does not fire on a named benign one; the grader runs both.
You leave withTetragon TracingPolicies with kprobe hooks catching real behaviors, tuned to exclude the benign cases that flood a naive policy.
Course 02
Network visibility
Every flow, identity-aware, so lateral movement shows up as a flow that should not exist. Hubble as the record and the alarm.
3 lessons · ~5 h
- 01Flows as evidenceIdentity-aware flow logs; the flow that should not exist as a detection.90 min
- 02Hubble in depthLive flow visibility, service maps, and DNS visibility for exfiltration over DNS.120 min
- 03Lateral movementWhat it looks like in flows; a detection and the policy that prevents it.90 min
Course checkFrom flow data, detect a simulated lateral-movement attempt and write the policy that would have stopped it.
You leave withHubble capturing identity-aware flows, a detection for an unexpected flow, and the network policy that closes it.
Course 03
Detection engineering
Turn a hypothesis about attacker behavior into a tested, version-controlled detection with a known false-positive rate, mapped to ATT&CK.
4 lessons · ~7 h
- 01From hypothesis to detectionAn attacker behavior turned into a precise, testable rule.90 min
- 02SigmaPortable detections in Sigma; the same rule against two backends.120 min
- 03Precision and recallTuning a detection to a false-positive budget; the cost of getting it wrong either way.90 min
- 04Mapping to ATT&CKCoverage as a grid; the gaps that decide what you write next.90 min
Course checkWrite three Sigma detections for given techniques, tune each to a false-positive budget, and map them to ATT&CK.
You leave withA set of Sigma detections in git, each tested against benign and malicious samples, each mapped to an ATT&CK technique.
Course 04
The detection pipeline and SIEM
Get events from everywhere to one place at scale: Tetragon and Hubble and app logs streamed through Kafka into a SIEM you built, not one you rent.
4 lessons · ~7 h
- 01Events at scaleWhy the bus: Tetragon, Hubble and app logs through Kafka instead of point-to-point.120 min
- 02The SIEMLoki and VictoriaMetrics as the store; retention, tenancy, and the query that answers a hunt.120 min
- 03EnrichmentJoining events to identity and asset context so an alert carries its own explanation.90 min
- 04Threat intelligence feedsIngesting indicators and matching them against the stream, without drowning in noise.90 min
Course checkBuild a pipeline that ingests three event sources through Kafka into the SIEM and answers a hunt query across all of them.
You leave withA detection pipeline streaming runtime, network and application events through Kafka into Loki and VictoriaMetrics, with a hunt query that spans them.
Course 05
Alerting and incident response
An alert that reaches a human with the context to act, an on-call that is humane, and an incident run to a clean forensic timeline.
4 lessons · ~7 h
- 01Alerting to a humanThresholds you justified, routing to chat, and a runbook link that resolves; alert rules that fire for real reasons.90 min
- 02On-call that is humaneRotation, escalation, and alert fatigue as a design problem.90 min
- 03Incident responseDetect, contain, eradicate, recover; roles and the first five minutes.120 min
- 04Forensics and the timelinePreserving evidence and reconstructing what happened, in order, from your own telemetry.120 min
Course checkGiven a firing alert, run the incident to containment and produce a timeline that would survive a review.
You leave withAlerts routed to chat with runbook links, an on-call rotation and escalation, and a forensic timeline you produced from a simulated incident.
Certification course
H2 Certified Threat Detection Engineer
$499 · one price · courses + 90-day labs + exam
A live intrusion across your stack: initial access, privilege escalation, lateral movement and exfiltration. Detect each stage, contain it, and produce a forensic timeline from your own telemetry.
Opens when Foundation is complete and the 5 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.
Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.
Create an account to enrol