UNF Professional and Lifelong Learning
UNF Professional and Lifelong Learning · Centri

Certified Detection Engineering Associate (CDEA) Training

LevelAssociate
DurationOn-demand · approx. 40 hours
Course codeCDEA
DeliveryInstructor-led

Offered to the Jacksonville and Northeast Florida community through UNF Professional and Lifelong Learning in partnership with Applied Technology Academy — live online or in person, taught by ATA's practitioner instructors.

Centri's Certified Detection Engineering Associate builds the practical skill of writing detections that work: Sigma and YARA rules, Zeek and network telemetr

Course Overview

Fifteen modules from networking, Windows, Linux and Python fundamentals through to detection rule creation, tuning and behavioural analytics.

  • Built around the work itself — writing rules, testing them, and cutting the noise until what reaches the SOC is worth acting on.
  • Treats detection content as code: Git workflows, review and release are part of the syllabus, not an afterthought.
  • Certification is a practical exam, and the credential is for life.
Prerequisites
  • Centri recommends one to three years of experience in cybersecurity.
  • Comfort with networking, Windows and Linux fundamentals helps, though the course covers each of them.
  • No prior detection-engineering experience is assumed.
What You'll Learn

By the end of this course, participants will be able to:

  • write and test detection rules in Sigma and YARA
  • use Zeek and network telemetry as a detection source
  • create and tune SIEM rules so that alerting is actionable rather than noisy
  • manage detection content through Git workflows with review and release
  • extract detection-worthy behaviour and indicators from malware analysis
  • turn threat intelligence into working detection content
  • apply behavioural analytics where static indicators fall short
  • judge where AI assists detection work and where it does not
Course Outline
  • Module 1. Networking Essentials The network fundamentals detection work rests on.
  • Module 2. Windows Essentials
    • Windows internals and the telemetry they produce.
  • Module 3. Linux Essentials
    • Linux fundamentals, services and logging.
  • Module 4. Python Essentials
    • Scripting for detection engineering tasks.
  • Module 5. Incident Response Essentials
    • How detections feed the response process.
  • Module 6. Git Workflows for Detection Engineering
    • Version control for detection content: branching, review and release.
  • Module 7. Network Analysis Essentials
    • Reading traffic with Wireshark and TCPDump.
  • Module 8. YARA & Sigma Essentials
    • Writing portable detection rules in both formats.
  • Module 9. Zeek Essentials
    • Network security monitoring and Zeek logs as a detection source.
  • Module 10. Malware Analysis for Detection Engineering
    • Extracting detection-worthy behaviour and indicators from samples.
  • Module 11. Detection Rule Creation and Tuning
    • Building rules, then tuning them down to a signal a SOC can actually work.
  • Module 12. Threat Intelligence Integration for Detection
    • Turning intelligence into detection content.
  • Module 13. Behavioural Analytics for Threat Detection
    • Detecting on behaviour rather than static indicators.
  • Module 14. AI for Defenders
    • Where AI helps detection work, and where it does not.
  • Module 15. CDEA Exam Preparation
    • Consolidation and practice ahead of the practical exam.