Centri Authorized Training

Certified Detection Engineering Associate (CDEA) Training

Centri's Certified Detection Engineering Associate builds the practical skill of writing detections that work: Sigma and YARA rules, Zeek and network telemetry, SIEM rule creation and tuning, and the Git workflows that keep detection content reviewable and releasable. It closes on behavioural analytics, threat-intelligence integration and where AI genuinely helps a defender. Certification is by practical exam and does not expire. ATA is Centri's exclusive US instructor-led partner.

LevelAssociate
DurationOn-demand · approx. 40 hours
Course codeCDEA
DeliveryInstructor-led
Course Overview

Fifteen modules from networking, Windows, Linux and Python fundamentals through to detection rule creation, tuning and behavioural analytics.

  • Built around the work itself — writing rules, testing them, and cutting the noise until what reaches the SOC is worth acting on.
  • Treats detection content as code: Git workflows, review and release are part of the syllabus, not an afterthought.
  • Certification is a practical exam, and the credential is for life.
Who Should Attend
  • SOC analysts moving from consuming detections to writing them.
  • Detection engineers and SIEM administrators who want a structured grounding.
  • Incident responders and threat intelligence analysts who need their findings to become durable detections.
  • Security engineers responsible for detection coverage.
Prerequisites
  • Centri recommends one to three years of experience in cybersecurity.
  • Comfort with networking, Windows and Linux fundamentals helps, though the course covers each of them.
  • No prior detection-engineering experience is assumed.
What You'll Learn

By the end of this course, participants will be able to:

  • write and test detection rules in Sigma and YARA
  • use Zeek and network telemetry as a detection source
  • create and tune SIEM rules so that alerting is actionable rather than noisy
  • manage detection content through Git workflows with review and release
  • extract detection-worthy behaviour and indicators from malware analysis
  • turn threat intelligence into working detection content
  • apply behavioural analytics where static indicators fall short
  • judge where AI assists detection work and where it does not
Course Outline
  • Module 1. Networking Essentials The network fundamentals detection work rests on.
  • Module 2. Windows Essentials
    • Windows internals and the telemetry they produce.
  • Module 3. Linux Essentials
    • Linux fundamentals, services and logging.
  • Module 4. Python Essentials
    • Scripting for detection engineering tasks.
  • Module 5. Incident Response Essentials
    • How detections feed the response process.
  • Module 6. Git Workflows for Detection Engineering
    • Version control for detection content: branching, review and release.
  • Module 7. Network Analysis Essentials
    • Reading traffic with Wireshark and TCPDump.
  • Module 8. YARA & Sigma Essentials
    • Writing portable detection rules in both formats.
  • Module 9. Zeek Essentials
    • Network security monitoring and Zeek logs as a detection source.
  • Module 10. Malware Analysis for Detection Engineering
    • Extracting detection-worthy behaviour and indicators from samples.
  • Module 11. Detection Rule Creation and Tuning
    • Building rules, then tuning them down to a signal a SOC can actually work.
  • Module 12. Threat Intelligence Integration for Detection
    • Turning intelligence into detection content.
  • Module 13. Behavioural Analytics for Threat Detection
    • Detecting on behaviour rather than static indicators.
  • Module 14. AI for Defenders
    • Where AI helps detection work, and where it does not.
  • Module 15. CDEA Exam Preparation
    • Consolidation and practice ahead of the practical exam.
Follow-On Courses

Related training topics

Get approved to attend

Justify your training

Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.

Sample training request letter

Subject: Request for Defensive Cyber & Blue Teaming training from Applied Technology Academy

[Decision Maker Name],

I'm writing to request time and budget approval to complete Applied Technology Academy's course, Certified Detection Engineering Associate (CDEA) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.

Course Description
Centri's Certified Detection Engineering Associate builds the practical skill of writing detections that work: Sigma and YARA rules, Zeek and network telemetry, SIEM rule creation and tuning, and the Git workflows that keep detection content reviewable and releasable. It closes on behavioural analytics, threat-intelligence integration and where AI genuinely helps a defender. Certification is by practical exam and does not expire. ATA is Centri's exclusive US instructor-led partner. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2019) whose instructors are active practitioners. The course combines instructor-led training with practical exercises, real-world examples, and computer-based activities designed to reinforce job-relevant skills.

Course Objectives
Once I've completed the course, I'll be able to:

  • By the end of this course, participants will be able to:
  • write and test detection rules in Sigma and YARA
  • use Zeek and network telemetry as a detection source
  • create and tune SIEM rules so that alerting is actionable rather than noisy
  • manage detection content through Git workflows with review and release
  • extract detection-worthy behaviour and indicators from malware analysis
  • turn threat intelligence into working detection content
  • apply behavioural analytics where static indicators fall short

Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.

Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.

Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in Defensive Cyber & Blue Teaming. Additional course information is available at https://appliedtechnologyacademy.com/centri-training/certified-detection-engineering-associate-cdea/.

Thank you for your consideration,
[Your Name]

Design training around your team, not the other way around.

Talk to a training advisor about private cohorts, funding paths and program management.

Request a Quote Call 800.674.3550