Event details
Mandiant Academy Training Event
- Course: ThreatSpace: Triage and Investigations Workshop (in-person)
- Date: Tuesday, September 22, 2026 – Wednesday, September 23, 2026
- Time: 8:30 AM–4:30 PM, daily
- Time Zone: (UTC+10:00) Sydney
- Cost: $4,000 USD or 4 units
- Delivery Method: Instructor-led, in-person delivery and remote delivery
- Location:
Google Sydney Office
48 Pirrama Rd
Pyrmont NSW 2009
Australia - DO NOT BOOK TRAVEL UNTIL September 1, 2026.
Mandiant Academy reserves the right to cancel this course until August 31, 2026. - Location for Remote Delivery registrants: Google Meet
At a glance
ThreatSpace is an engaging practical focused activity offered by Mandiant. In this 2 day delivery, security professionals will access a virtual environment that simulates real-world IT infrastructure, including network segments, workstations, servers, and applications. This instructor-led workshop will progress participants through different triage and investigations skill sets as well as provide exposure to different threat tactics including investigation soft skills. The workshop focuses on ensuring skills to appropriately triage a range of threats and effectively transition to investigation as part of the incident response process using specific IR skillsets.
Course goals
TheatSpace comes in varying formats based on the training requirement for individuals and teams. This offering is focused on individuals and providing security professionalss with real world exposure to threats and their TTPs. This workshop will be broken down into small theory packages followed by practical hands on exposure, with mentoring throughout.
In this workshop, participants can learn to:
- Describe triage practices.
- Develop processes to confirm suspicious and malicious activities.
- Demonstrate triage practices after identifying security events of interest.
- Demonstrate investigation progress via indicator pivoting.
- Develop a timeline of malicious activity.
- Describe an analyst’s responsibilities within the triage phase of a response.
- Describe an analyst’s responsibilities within the investigation phase of a response.
Who this course helps
This offering is designed for junior to senior responders with some incident response training including courses like Windows or Linux Enterprise Incident Response.
What to bring
Students should bring their own laptop computer with the latest browser of choice and the ability to connect to the Internet. Students will receive directions on how to connect to the lab environment.
Course materials
Students will be provided access to all required class materials and tools.


