Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Core principles and professional responsibilities
  • The detection engineering lifecycle
  • Essential tools and telemetry sources

Understanding Log Sources

  • Endpoint logs and event artifacts
  • Network traffic patterns and flow data
  • Cloud infrastructure and identity provider logs

Threat Intelligence for Detection

  • Categorizations of threat intelligence
  • Utilizing TI to guide detection design
  • Aligning threats with specific log sources

Creating Robust Detection Rules

  • Rule logic and pattern architecture
  • Distinguishing between behavioral and signature-based activity
  • Implementing Sigma, Elastic, and SO rules

Alert Tuning and Optimization

  • Reducing the volume of false positives
  • Iterative refinement of detection rules
  • Contextual understanding of alerts and threshold settings

Investigation Methodologies

  • Verifying the accuracy of detections
  • Pivoting across multiple data sources
  • Recording findings and investigation notes

Implementing Detections Operationally

  • Version control and change management practices
  • Deploying rules to production environments
  • Tracking rule performance over extended periods

Advanced Concepts for Junior Engineers

  • Alignment with MITRE ATT&CK framework
  • Data normalization and parsing techniques
  • Exploring automation potential in detection workflows

Conclusion and Future Directions

Requirements

  • A solid grasp of fundamental networking principles
  • Proficiency in operating environments such as Windows or Linux
  • Knowledge of core cybersecurity terminology

Target Audience

  • Junior analysts with an interest in security monitoring
  • Newly appointed SOC team members
  • IT professionals transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories