TrainSec Launches Detection Engineering Professional Course, Offers Scholarships of Up to 30% for Individual Students and Freelancers

September 14 10:09 2026
TrainSec Launches Detection Engineering Professional Course, Offers Scholarships of Up to 30% for Individual Students and Freelancers
“Security teams are not short on alerts. They are short on people who can write a detection, prove it fires, and then find the way around it before an attacker does. That is the job this course trains for. We added scholarships because many of the practitioners who need this skill most are paying for their training out of their own pocket.” – Uriel Kosayev, co-founder of TrainSec and instructor of Detection Engineering Professional
TrainSec has launched Detection Engineering Professional: Attack Simulation & Defense, a 147-lesson course taught by co-founder Uriel Kosayev. Students simulate attacker techniques in a Windows Active Directory lab, trace them through Event Logs, Sysmon and EDR telemetry, then write, tune and validate their own detection rules. Scholarships of up to 30% are open to individual students and self-paying freelancers.

TENAFLY, N.J. – September 14, 2026 – TrainSec, the online cybersecurity training academy, today announced the launch of Detection Engineering Professional: Attack Simulation & Defense, a hands-on course for security practitioners who want to move from triaging alerts to writing the detections behind them. The course is taught by TrainSec co-founder Uriel Kosayev, author of Antivirus Bypass Techniques and MAoS: Malware Analysis on Steroids.

To widen access, TrainSec is offering scholarships of up to 30% off the course price to individual students and self-paying freelancers.

From recognizing attacks to owning the detections

Much security training teaches people to recognize an attack after the fact. Detection Engineering Professional is built around the work of the detection engineer: the person who decides what gets caught in the first place.

Every attack-and-defense module follows the same five-step cycle used in production detection engineering:

  1. Simulate the attacker technique in a controlled Windows Active Directory lab
  2. Investigate it across the telemetry it produces, and identify which data sources saw it and which were blind
  3. Detect it with a rule written against the durable artifact the attack leaves behind, not the tool that created it
  4. Tune the rule by measuring alert volume and excluding legitimate activity
  5. Validate it by re-running the attack to prove the rule fires, then attempting to bypass it and closing the gap

Students apply this cycle to lateral movement over RDP, PsExec, WinRM and WMI, Active Directory discovery, living-off-the-land techniques, registry and service persistence, LSASS credential dumping, and process injection. Along the way they build Sysmon configurations from scratch, deploy and harden Elastic Defend, write KQL detection rules with MITRE ATT&CK tagging, and learn to use AI-assisted detection engineering while validating every answer against the product itself.

“Security teams are not short on alerts. They are short on people who can write a detection, prove it fires, and then find the way around it before an attacker does. That is the job this course trains for. We added scholarships because many of the practitioners who need this skill most are paying for their training out of their own pocket,” said Uriel Kosayev, co-founder of TrainSec and instructor of Detection Engineering Professional.

Who the course is for

Detection Engineering Professional is an advanced course for practitioners with hands-on experience in SOC operations, penetration testing or incident response. It serves defenders who want to build rules instead of only reading their output, and offensive security professionals who want to see their own techniques from the defender’s side of the SIEM.

Scholarships for individuals and freelancers

Scholarships of up to 30% off are available to individual students and self-paying freelancers, the practitioners who fund their own professional development without an employer training budget.

Course details

  • Course: Detection Engineering Professional: Attack Simulation & Defense
  • Instructor: Uriel Kosayev, co-founder of TrainSec
  • Content: 147 lessons, more than 14.5 hours of video, self-paced
  • Includes: Lifetime access, certificate of completion, access to the TrainSec Discord community, 14-day money-back guarantee
  • Price: $700, or a payment plan of 5 x $149
  • Scholarships: Up to 30% off for individual students and self-paying freelancers


Learn more:
https://trainsec.net/courses/detection-engineering-attack-simulation-defense/

About Uriel Kosayev

Uriel Kosayev is a cybersecurity researcher and reverse engineer with more than a decade of experience in malware analysis, offensive security and incident response. He is the author of Antivirus Bypass Techniques, which has sold more than 8,000 copies, and MAoS: Malware Analysis on Steroids (2025). He has published academic white papers on malware detection and memory-based threats, and has contributed research to the MITRE ATT&CK framework. At TrainSec he teaches the malware analysis and security track.

About TrainSec

TrainSec (trainsec.net) is an online cybersecurity training academy built on the principle that professionals train professionals. Its self-paced courses and live workshops are taught by practitioners with deep hands-on expertise in Windows internals, malware analysis, detection engineering and hardware security. TrainSec also publishes a free knowledge library of technical research and practitioner writing for the wider security community.

Media Contact [email protected], https://trainsec.net

Media Contact
Company Name: Scorpio Software LLC
Contact Person: Mickey Zelansky
Email: Send Email
Phone: 5513464575
Address:95 Newcomb Rd.
City: Tenafly
State: NJ
Country: United States
Website: https://trainsec.net

view more articles

About Article Author