Skip to content
Academy · Cybersecurity · advanced

HIGAET Cyber Defense Engineering

Learn layered defense design and build network controls, endpoint defenses, deception sensors, and coordinated response drills in isolated labs.

Duration

10 weeks · 6-8 hours/week

Level

Advanced

Delivery

Hybrid

Status

Open for enrollment

Introduction

Why this technology matters.

Cyber defense engineering is the practice of designing layered defenses so that if one control fails, others still catch the attack. It matters now because single-point defenses are easily bypassed, while coordinated network, endpoint, and deception layers give defenders multiple chances to detect intruders. This course teaches the layered approach through isolated labs and drills.

You will use these designs to protect networks and endpoints: layered defense layouts, detection coverage maps across network and host telemetry, and coordinated response runbooks for simulated scenarios. This solves single-layer fragility and blind spots between tools. It does not solve everything: more layers do not fix unpatched systems by themselves, coverage maps do not fix missing log quality, and drills do not fix unclear escalation authority.

By the end you will be able to build a layered defense layout for a lab network with endpoint defenses, a detection coverage map across network and host telemetry, and a coordinated response runbook paired with honeypot and alerting sensors in an isolated lab.

Why this course exists

The gap is between deploying individual security tools and engineering defenses that work as a system. This course closes it with an arc from layout to coverage to response: design layered network and endpoint defenses, map detection coverage across telemetry, then drill coordinated runbooks supported by deception sensors.

Overview

Know exactly what you're signing up for.

Who is this for

Security practitionersIT administratorsOperations staffCloud engineersSoftware developers

Prerequisites

  • Basic networking and endpoint familiarity
  • Comfort working in isolated virtual labs
  • Understanding of logs and alerts

Technologies & tools

Network controlsEndpoint defensesDetection coverage mapsHoneypotsAlerting sensorsResponse runbooksTelemetry dashboards

Skills you'll gain

Layered defense designNetwork controlsEndpoint defenseDetection coverage mappingDeception sensorsResponse runbooksDrill coordination
Curriculum

A 10 weeks arc, module by module.

  1. Module 01

    Module 01 — Foundations: Defense in depth and control families

  2. Module 02

    Module 02 — Network Defense: Segmentation, filtering, and monitoring

  3. Module 03

    Module 03 — Endpoint Defense: Baselines, allowlists, and EDR review

  4. Module 04

    Module 04 — Core: Detection mapping and coverage analysis

  5. Module 05

    Module 05 — Engineering: Deception sensors and alert validation

  6. Module 06

    Module 06 — Coordination: Response roles and communication drills

  7. Module 07

    Module 07 — Resilience: Backup, restore, and continuity checks

  8. Module 08

    Module 08 — Exercise: Controlled blue-team simulation and review

  9. Module 09

    Module 09 — Capstone: Integrated defense lab with exercise report

Practical Training Flow

Learning → Guided Labs → Independent Practice → Industry Project → Capstone → Portfolio → Career Preparation. Practical hours are tracked alongside instructional hours and surfaced on the certificate.

Delivery as HIGAET Practical Training / Experiential Learning.

cyber defenseblue teamdetection mappingnetwork securityedr reviewdeception technologyincident drillsresiliencehigaet academy
Outcomes

What you'll be able to do.

  • Build layered defense layouts for lab networks and endpoints
  • Design detection coverage maps across network and host telemetry
  • Develop coordinated response runbooks for simulated scenarios
  • Deploy honeypots and alerting sensors in isolated labs
  • Integrate firewall, EDR, and log controls into one view
  • Evaluate adversary tactics using defensive mapping frameworks
  • Secure recovery workflows with backups and rehearsal checklists
  • Automate evidence packaging for post-exercise reviews
Projects

You will build.

Every project ships as HIGAET Practical Training / Experiential Learning — portfolio-ready work, not exercises.

  1. Project 01

    Layered defense lab layout

  2. Project 02

    Network and host detection coverage map

  3. Project 03

    Isolated honeypot sensor deployment

  4. Project 04

    Coordinated response runbook set

  5. Capstone

    Layered lab defense with controls, sensors, coverage maps, and response drill

Key concepts

Speak the language first.

Layered defense
Stacking network, endpoint, and monitoring controls so one missed attack still meets another barrier.
Network security controls
Firewalls, segmentation, and filtering rules that limit how traffic moves between lab zones.
Endpoint defenses
Hardening, antivirus, and configuration controls that protect individual lab workstations and servers.
Detection coverage map
A chart showing which attack techniques are visible in network versus host telemetry and where gaps remain.
Host and network telemetry
Logs and sensor data from computers and network devices used to spot suspicious defensive events.
Deception sensors
Decoy systems and honeypots placed in isolated labs to attract and reveal attacker-like activity safely.
Response runbooks
Written step-by-step guides teams follow to contain, investigate, and recover from simulated incidents.
Coordinated response drills
Practice exercises where defenders rehearse roles, communication, and handoffs during a mock scenario.
Alert tuning
Adjusting detection thresholds and filters so real threats stand out with fewer false alarms.
Keep going

Fix, check, and go deeper.

Troubleshooting & common mistakes

Honeypot generates no alerts during a drill

Verify network routes and firewall rules allow lab traffic to reach the sensor, then confirm the alerting agent is running and forwarding.

Coverage map shows blind spots in host telemetry

Audit which agents are installed and reporting, reinstall or reconfigure missing ones, and re-collect a day of logs.

Runbook steps conflict between network and endpoint teams

Walk through the runbook in a tabletop review, assign clear owners per step, and update handoff order before the next drill.

Too many noisy alerts drown out drill objectives

Raise thresholds or add exclusion filters for known lab noise, then re-baseline detection on a quiet capture window.

Segmentation blocks legitimate lab monitoring traffic

Trace the blocked flow in firewall logs, add a narrow allow rule for the monitoring collector, and re-test sensor visibility.

Before you move on, you should be able to

  • Build layered defense layouts for lab networks and endpoints
  • Design detection coverage maps across network and host telemetry
  • Develop coordinated response runbooks for simulated scenarios
  • Deploy honeypots and alerting sensors in isolated labs
  • Explain how layered controls limit attacker movement
  • Evaluate drill results to close detection and response gaps
Apply

Start your application.

Share a few details and a HIGAET advisor will reach out within one business day with next steps.

FAQ

Common questions

Ready to start HIGAET Cyber Defense Engineering?

A 10 weeks course — Cybersecurity.