Get in Touch
 Duration 21 hours

Course Outline

Basics of Detection Engineering

  • Essential concepts and role responsibilities
  • The detection engineering lifecycle
  • Primary tools and telemetry origins

Navigating Log Sources

  • Endpoint logs and event records
  • Network traffic and flow information
  • Cloud and identity provider logs

Applying Threat Intelligence to Detection

  • Categories of threat intelligence
  • Incorporating TI into detection design
  • Connecting threats to pertinent log sources

Crafting Effective Detection Rules

  • Rule logic and pattern frameworks
  • Identifying behavioral versus signature-based activities
  • Implementing Sigma, Elastic, and SO rules

Tuning and Optimizing Alerts

  • Reducing false positives
  • Refining rules through iteration
  • Comprehending alert context and thresholds

Investigation Methods

  • Verifying detections
  • Pivoting among data sources
  • Recording findings and investigation notes

Implementing Detections Operationally

  • Version control and change management
  • Rolling out rules to production environments
  • Tracking rule performance over time

Advanced Insights for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing
  • Automation potential in detection workflows

Recap and Future Directions

Requirements

  • A solid grasp of fundamental networking principles
  • Practical experience with operating systems like Windows or Linux
  • Acknowledgment of core cybersecurity vocabulary

Intended Audience

  • Junior analysts focused on security monitoring
  • Recent hires joining SOC teams
  • IT professionals transitioning into detection engineering

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories