Get in Touch
 Duration 21 hours

Course Outline

Principles of Detection Engineering

  • Core concepts and professional responsibilities
  • The end-to-end detection engineering lifecycle
  • Essential tools and telemetry origins

Identifying Log Sources

  • Endpoint logs and event artifacts
  • Network traffic patterns and flow data
  • Logs from cloud services and identity providers

Integrating Threat Intelligence

  • Classifications of threat intelligence
  • Leveraging intelligence to guide detection design
  • Correlating threats with specific log sources

Constructing Robust Detection Rules

  • Rule logic and structural patterns
  • Distinguishing behavioral from signature-based activity
  • Implementation using Sigma, Elastic, and SO rules

Tuning and Optimizing Alerts

  • Strategies for reducing false positives
  • Process of iterative rule refinement
  • Comprehension of alert context and threshold settings

Investigative Methodologies

  • Verification of detected events
  • Navigating across multiple data sources
  • Recording findings and investigation notes

Implementing Detections Operationally

  • Version control and change management practices
  • Deployment of rules to live production systems
  • Tracking rule performance over extended periods

Advanced Topics for Junior Engineers

  • Alignment with the MITRE ATT&CK framework
  • Techniques for data normalization and parsing
  • Exploring automation opportunities within detection workflows

Recap and Future Directions

Requirements

  • A foundational grasp of basic networking concepts
  • Practical experience with operating systems such as Windows or Linux
  • Knowledge of core cybersecurity terminology

Target Audience

  • Junior analysts with an interest in security monitoring
  • Newly integrated SOC team members
  • IT professionals transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories