ExploreGalaxyMy PathSettingsGive Feedback

New here?

A quick look at how MySkillGap works. Close it any time.

Skill Profile

Threat Detection

Security / Technical

"Identifying indicators of compromise, malicious activity, or security anomalies within systems, networks, and logs before they escalate into incidents."

YOUR SKILLS

Problems This Skill Solves

  • An attacker establishes a foothold that goes undetected for months — threat detection closes the dwell time window
  • The security team is drowning in false positive alerts — effective detection engineering tunes rules to reduce noise
  • A new attack technique isn't matched by existing signatures — threat hunting proactively searches for unknown threats based on behaviour
Myths vs Truths
Myth

"If you have a SIEM, you have threat detection."

Truth

A SIEM is a platform, not a detection capability. It collects and correlates data, but detection quality depends entirely on the quality of the rules, tuning, and analysts operating it.

Myth

"AI will handle threat detection soon."

Truth

AI tools improve detection rate and speed, but attackers adapt. Human analysts who understand attacker behaviour and business context remain essential for high-quality threat detection.

Research & Outlook

AI-powered threat detection is augmenting analysts but human judgement in alert triage remains essential.

See This Skill In Action

Watch a professional demonstrate Threat Detection in a real working environment — what it looks like, how it's applied, and why it matters.

Threat Detection in practice
A professional demonstrates this skill on the job
Subscribe for updates

Security / Technical

Threat Detection

0roles unlock with this skill

Growth Path

Beginner

Can triage SIEM alerts using established playbooks and identify obvious indicators of compromise in log data.

Intermediate

Writes detection rules for known threat techniques, conducts threat hunts using hypothesis-driven approaches, and reduces alert fatigue through tuning.

Expert

Designs a detection engineering programme, develops detection for novel threats, integrates threat intelligence into detection pipelines, and leads the SOC's technical capability development.

How to Practise

  • 1.Set up a SIEM lab using Splunk Free or Microsoft Sentinel in Azure and ingest sample security logs
  • 2.Write detection rules in Sigma for common attack patterns from MITRE ATT&CK
  • 3.Complete SOC analyst training on platforms like LetsDefend, Blue Team Labs Online, or CyberDefenders

How to Prove

  • ·GIAC GCDA (Certified Detection Analyst) or CompTIA CySA+ certification
  • ·Detection rules published to the Sigma GitHub repository
  • ·SOC analyst employment history with measurable detection and response metrics