Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Principles of Detection Engineering
- Core concepts and professional responsibilities
- The end-to-end detection engineering lifecycle
- Essential tools and telemetry origins
Identifying Log Sources
- Endpoint logs and event artifacts
- Network traffic patterns and flow data
- Logs from cloud services and identity providers
Integrating Threat Intelligence
- Classifications of threat intelligence
- Leveraging intelligence to guide detection design
- Correlating threats with specific log sources
Constructing Robust Detection Rules
- Rule logic and structural patterns
- Distinguishing behavioral from signature-based activity
- Implementation using Sigma, Elastic, and SO rules
Tuning and Optimizing Alerts
- Strategies for reducing false positives
- Process of iterative rule refinement
- Comprehension of alert context and threshold settings
Investigative Methodologies
- Verification of detected events
- Navigating across multiple data sources
- Recording findings and investigation notes
Implementing Detections Operationally
- Version control and change management practices
- Deployment of rules to live production systems
- Tracking rule performance over extended periods
Advanced Topics for Junior Engineers
- Alignment with the MITRE ATT&CK framework
- Techniques for data normalization and parsing
- Exploring automation opportunities within detection workflows
Recap and Future Directions
Requirements
- A foundational grasp of basic networking concepts
- Practical experience with operating systems such as Windows or Linux
- Knowledge of core cybersecurity terminology
Target Audience
- Junior analysts with an interest in security monitoring
- Newly integrated SOC team members
- IT professionals transitioning into detection engineering roles
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.