Winter Semester · TH Rosenheim

Security Analytics (SecA)

TH RosenheimWinter SemesterProf. Dr.-Ing. Kevin Mayer

Security Analytics (SecA)

This is the course “Security Analytics (SecA)” given each winter semester at the Technische Hochschule Rosenheim.

The responsible professor is Prof. Dr.-Ing. Kevin Mayer.

The module SecA introduces the Security Information and Event Management (SIEM) toolchain, a lab environment, and core security analysis skills. Students will work through a fictional cyber security incident, specifically a phishing triage with basic network traffic analysis. The course covers anomaly detection via statistical baselines, threat intelligence integration, and SIEM correlation rule engineering. Students write detection rules for observed indicators. Further, a deep dive into the Incident Response workflow, memory forensics, and introductory malware analysis is conducted. Students produce a full memory and malware analysis report. The course explores Machine-Learning-based log analysis and hypothesis-driven threat hunting. The course ties together the full attack chain attribution, reporting, and dashboard design to give the students a broad skillset for cyber security defense operations.

The lecture concept was awarded with the Lehrförderpreis in 2026.

Labs and reports

The labs happen after each larger module. You have 72 hours to submit the report on Learning Campus (coming soon). See the due dates and hours in the table below.

Important: You must have submitted at least 3 reports to be eligible for the exam. You may need to revise a report.

Schedule

The lecture is on each Thursday from 8:00-11:15 in room B0.08.

There will be a on-site lecture with a connected exercise. You can also prepare in advance using the coming soon.

Date What we cover Exercise Preparation Due?
01.10.2026 Course Intro & SIEM Basics E0 Section 1.1 SIEM Basics -
08.10.2026 Log Analysis E1 Section 1.2 Log Analysis -
15.10.2026 Network Trafic Analysis E2 Section 1.3 Network Tra!c Analysis -
15.10.2026 Publish lab 1 material - 16:00:00 (GMT+2)
18.10.2026 Lab 1 report submission - 16:00:00 (GMT+2)
22.10.2026 Anomaly Detection E3 Section 2.1 Anomaly Detection -
29.10.2026 Threat Intelligence E4 Section 2.2 Threat Intelligence -
05.11.2026 IOCs and TTPs E5 Section 2.3 IoCs and TTPs -
12.11.2026 Signatures and Correlation Rules E6 Section 2.4 Signatures and Correlation Rules -
12.11.2026 Publish lab 2 material - 16:00:00 (GMT+2)
15.11.2026 Lab 2 report submission - 16:00:00 (GMT+2)
19.11.2026 Incident Response E7 Section 3.1 Incident Response -
26.11.2026 Digital Forensics E8 Section 3.2 Digital Forensics -
03.12.2026 Malware Analysis E9 Section 3.3 Malware Analysis -
03.12.2026 Publish lab 3 material - 16:00:00 (GMT+2)
06.12.2026 Lab 3 report submission - 16:00:00 (GMT+2)
10.12.2026 Machine Learning for Security E10 Section 4.1 Machine Learning for Security -
17.12.2026 Legal Aspects E11 Section 4.2 Legal Aspects -
07.01.2027 Threat Hunting E12 Section 4.3 Threat Hunting -
07.01.2027 Publish lab 4 material - 16:00:00 (GMT+2)
10.01.2027 Lab 4 report submission - 16:00:00 (GMT+2)
14.01.2027 MITRE ATT&CK E13 Section 4.4 MITRE ATT&CK -
21.01.2027 Exam Prep - -