Skill Profile
Threat Detection
"Identifying indicators of compromise, malicious activity, or security anomalies within systems, networks, and logs before they escalate into incidents."
YOUR SKILLS
Problems This Skill Solves
- An attacker establishes a foothold that goes undetected for months — threat detection closes the dwell time window
- The security team is drowning in false positive alerts — effective detection engineering tunes rules to reduce noise
- A new attack technique isn't matched by existing signatures — threat hunting proactively searches for unknown threats based on behaviour
"If you have a SIEM, you have threat detection."
A SIEM is a platform, not a detection capability. It collects and correlates data, but detection quality depends entirely on the quality of the rules, tuning, and analysts operating it.
"AI will handle threat detection soon."
AI tools improve detection rate and speed, but attackers adapt. Human analysts who understand attacker behaviour and business context remain essential for high-quality threat detection.
Research & Outlook
AI-powered threat detection is augmenting analysts but human judgement in alert triage remains essential.
See This Skill In Action
Watch a professional demonstrate Threat Detection in a real working environment — what it looks like, how it's applied, and why it matters.
Security / Technical
Threat Detection
Connected Skills
Growth Path
Can triage SIEM alerts using established playbooks and identify obvious indicators of compromise in log data.
Writes detection rules for known threat techniques, conducts threat hunts using hypothesis-driven approaches, and reduces alert fatigue through tuning.
Designs a detection engineering programme, develops detection for novel threats, integrates threat intelligence into detection pipelines, and leads the SOC's technical capability development.
How to Practise
- 1.Set up a SIEM lab using Splunk Free or Microsoft Sentinel in Azure and ingest sample security logs
- 2.Write detection rules in Sigma for common attack patterns from MITRE ATT&CK
- 3.Complete SOC analyst training on platforms like LetsDefend, Blue Team Labs Online, or CyberDefenders
How to Prove
- ·GIAC GCDA (Certified Detection Analyst) or CompTIA CySA+ certification
- ·Detection rules published to the Sigma GitHub repository
- ·SOC analyst employment history with measurable detection and response metrics