Detect an incident, qualify it and respond to it by a written procedure.
Next intake: Monday 5 October, with enrolment open until 2 October. The following one starts on 4 January 2027.
Choose the sources to log and discard those that cost without adding anything
Centralise, timestamp, normalise and enrich events
Place an attack technique within the MITRE ATT&CK framework
Write, test and tune a detection rule
Triage an alert by severity, scope and urgency
Contain, eradicate and restore service while preserving evidence
Use an AI assistant for triage without delegating the decision to it
Systematic alternation between short theory sessions and practical work, with most of the time spent on practice
Progression from simple to complex: each module builds on what was learnt in the previous one
Realistic role-plays drawn from Cameroonian business cases
Considered use of generative AI as a working tool, in line with the common core
Regular formative assessments and a final integrative project drawing on all four modules
Formative assessment at the end of each module (graded role-play and practical exercises)
Practical work assessed against competency sheets
Final integrative project, presented and defended before the trainer
One graded assignment per module in the online course space
Wazuh or Elastic — collection, normalisation and detection
Sysmon and Windows logs, systemd and auditd logs on Linux
MITRE ATT&CK framework and Atomic Red Team for detection testing
An analysis sandbox and harmless samples
An AI assistant with controlled instructions for alert triage
Sessions open every quarter. Apply now or request the detailed brochure — our advisers will get back to you.