Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Essential concepts and professional responsibilities
  • The lifecycle of detection engineering
  • Primary tools and telemetry origins

Understanding Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow information
  • Cloud and identity provider records

Threat Intelligence for Detection

  • Categorizations of threat intelligence
  • Integrating TI to guide detection design
  • Linking threats to pertinent log sources

Building Effective Detection Rules

  • Rule logic and pattern frameworks
  • Identifying behavioral versus signature-based actions
  • Utilizing Sigma, Elastic, and SO rules

Alert Tuning and Optimization

  • Reducing false positives
  • Continuous refinement of rules
  • Grasping alert context and thresholds

Investigation Techniques

  • Verifying detections
  • Correlating data across multiple sources
  • Recording findings and investigation details

Operationalizing Detections

  • Version control and change management
  • Implementing rules in production environments
  • Tracking rule performance over time

Advanced Concepts for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing
  • Automation prospects in detection processes

Summary and Next Steps

Requirements

  • A solid grasp of fundamental networking principles
  • Practical experience with operating systems such as Windows or Linux
  • Knowledge of basic cybersecurity terminology

Target Audience

  • Junior analysts with an interest in security monitoring
  • Newly appointed SOC team members
  • IT specialists transitioning into the field of detection engineering

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories