Junior Detection Engineer Essentials Training Course
Detection engineering involves the design, implementation, and refinement of techniques to identify malicious activities across systems and networks.
This instructor-led, live training, available online or onsite, is designed for beginner-level cybersecurity professionals seeking practical skills in creating and tuning security detections.
Upon completing this training, participants will possess the capabilities to:
- Create effective detection rules and signatures using standard security tools.
- Analyze logs and telemetry data to spot suspicious behavior.
- Leverage threat intelligence to enhance detection logic.
- Refine alerts and minimize false positives within a SOC environment.
Course Format
- Guided instruction accompanied by practical demonstrations.
- Scenario-based exercises and hands-on analysis.
- Real-world detection development in an interactive lab setting.
Customization Options
- For organizations needing a customized version of this program, please contact us to explore customization possibilities.
Course Outline
Foundations of Detection Engineering
- Core concepts and responsibilities
- The detection engineering lifecycle
- Key tools and telemetry sources
Understanding Log Sources
- Endpoint logs and event artifacts
- Network traffic and flow data
- Cloud and identity provider logs
Threat Intelligence for Detection
- Types of threat intelligence
- Using TI to inform detection design
- Mapping threats to relevant log sources
Building Effective Detection Rules
- Rule logic and pattern structures
- Detecting behavioral vs signature-based activity
- Using Sigma, Elastic, and SO rules
Alert Tuning and Optimization
- Minimizing false positives
- Iterative rule refinement
- Understanding alert context and thresholds
Investigation Techniques
- Validating detections
- Pivoting across data sources
- Documenting findings and investigation notes
Operationalizing Detections
- Versioning and change management
- Deploying rules to production systems
- Monitoring rule performance over time
Advanced Concepts for Junior Engineers
- MITRE ATT&CK alignment
- Data normalization and parsing
- Automation opportunities in detection workflows
Summary and Next Steps
Requirements
- A foundational understanding of networking concepts
- Experience using operating systems such as Windows or Linux
- Familiarity with basic cybersecurity terminology
Target Audience
- Junior analysts interested in security monitoring
- New members of a SOC team
- IT professionals transitioning into detection engineering
Open Training Courses require 5+ participants.
Junior Detection Engineer Essentials Training Course - Booking
Junior Detection Engineer Essentials Training Course - Enquiry
Junior Detection Engineer Essentials - Consultancy Enquiry
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.
Otilia Pasareti - Merthyr College
Course - Fundamentals of Corporate Cyber Warfare
Upcoming Courses
Related Courses
AI-Powered Cybersecurity: Threat Detection & Response
21 HoursThis instructor-led, live training in Argentina (online or onsite) is designed for entry-level cybersecurity professionals seeking to harness AI to enhance their threat detection and response capabilities.
Upon completion of this training, participants will be able to:
- Grasp the role of AI in cybersecurity.
- Deploy AI algorithms for effective threat detection.
- Streamline incident response using AI tools.
- Embed AI into current cybersecurity infrastructure.
AI-Powered Cybersecurity: Advanced Threat Detection & Response
28 HoursThis instructor-led, live training in Argentina (online or onsite) is designed for intermediate to advanced cybersecurity professionals aiming to enhance their capabilities in AI-driven threat detection and incident response.
Upon completion of this training, participants will be capable of:
- Deploying advanced AI algorithms for real-time threat detection.
- Tailoring AI models to address specific cybersecurity challenges.
- Creating automation workflows for threat response.
- Protecting AI-driven security tools from adversarial attacks.
Blue Team Fundamentals: Security Operations and Analysis
21 HoursThis instructor-led, live training in Argentina (online or onsite) is aimed at intermediate-level IT security professionals who wish to develop skills in security monitoring, analysis, and response.
By the end of this training, participants will be able to:
- Understand the role of a Blue Team in cybersecurity operations.
- Use SIEM tools for security monitoring and log analysis.
- Detect, analyze, and respond to security incidents.
- Perform network traffic analysis and threat intelligence gathering.
- Apply best practices in security operations center (SOC) workflows.
Bug Bounty Hunting
21 HoursBug Bounty Hunting involves identifying security vulnerabilities in software, websites, or systems and responsibly reporting them to receive rewards or recognition.
This instructor-led, live training (available online or onsite) is designed for beginner-level security researchers, developers, and IT professionals who wish to learn the fundamentals of ethical bug hunting and how to participate in bug bounty programs.
By the end of this training, participants will be able to:
- Understand the core concepts of vulnerability discovery and bug bounty programs.
- Use key tools like Burp Suite and browser dev tools for testing applications.
- Identify common web security flaws such as XSS, SQLi, and CSRF.
- Submit clear, actionable vulnerability reports to bug bounty platforms.
Format of the Course
- Interactive lecture and discussion.
- Hands-on use of bug bounty tools in simulated testing environments.
- Guided exercises focused on discovering, exploiting, and reporting vulnerabilities.
Course Customization Options
- To request a customized training for this course based on your organization's applications or testing needs, please contact us to arrange.
Bug Bounty: Advanced Techniques and Automation
21 HoursBug Bounty: Advanced Techniques and Automation provides an in-depth exploration of high-impact vulnerabilities, automation frameworks, reconnaissance methodologies, and the strategic tooling utilized by top-tier bug bounty hunters.
This instructor-led live training, available online or onsite, is designed for intermediate to advanced security researchers, penetration testers, and bug bounty hunters who aim to streamline their workflows, scale their reconnaissance efforts, and uncover complex vulnerabilities across diverse targets.
Upon completing this training, participants will be capable of:
- Automating reconnaissance and scanning processes for multiple targets.
- Utilizing state-of-the-art tools and scripts essential for bounty automation.
- Identifying complex, logic-based vulnerabilities that extend beyond standard scan results.
- Developing custom workflows for subdomain enumeration, fuzzing, and vulnerability reporting.
Course Format
- Interactive lectures and discussions.
- Practical application of advanced tools and scripting for automation purposes.
- Guided laboratory exercises focused on real-world bounty workflows and sophisticated attack chains.
Customization Options
- For tailored training based on your specific bounty targets, automation requirements, or internal security challenges, please contact us to arrange a customized session.
Cyber Defence (SOC) Analyst Foundation
7 HoursThis instructor-led, live training in Argentina (online or on-site) is tailored for beginner to intermediate-level security analysts and system administrators seeking to establish a foundational understanding of Cyber Defence (SOC) analysis.
By the conclusion of this training, participants will be able to:
- Understand the principles of Security Management in a Cyber Defence context.
- Execute effective Incident Response strategies to mitigate security incidents.
- Implement Security Education practices to enhance organizational awareness and preparedness.
- Manage and analyze Security Information for proactive threat identification.
- Utilize Event Management techniques to monitor and respond to security events.
- Implement Vulnerability Management processes to identify and address system vulnerabilities.
- Develop skills in Threat Detection to identify and respond to potential cyber threats.
- Participate in Simulated Attacks to test and improve incident response capabilities.
CHFI - Certified Digital Forensics Examiner
35 HoursThe vendor-neutral Certified Digital Forensics Examiner certification is designed to train Cyber Crime and Fraud Investigators by teaching them electronic discovery and advanced investigative techniques. This course is essential for anyone who encounters digital evidence while conducting an investigation.
The Certified Digital Forensics Examiner training provides the methodology for conducting a computer forensic examination. Students learn to apply forensically sound investigative techniques to evaluate the scene, collect and document all relevant information, interview appropriate personnel, maintain the chain-of-custody, and write a findings report.
The Certified Digital Forensics Examiner course benefits organizations, individuals, government offices, and law enforcement agencies interested in pursuing litigation, establishing proof of guilt, or taking corrective action based on digital evidence.
Certified Incident Handler
21 HoursThe Certified Incident Handler course offers a structured methodology for effectively and efficiently managing and responding to cybersecurity incidents.
This instructor-led live training, available online or onsite, is designed for intermediate-level IT security professionals aiming to acquire the tactical skills and knowledge necessary to plan, classify, contain, and manage security incidents.
Upon completion of this training, participants will be able to:
- Grasp the incident response lifecycle and its distinct phases.
- Car out incident detection, classification, and notification procedures.
- Implement containment, eradication, and recovery strategies effectively.
- Formulate post-incident reporting and continuous improvement plans.
Course Format
- Interactive lectures and discussions.
- Practical application of incident handling procedures in simulated scenarios.
- Guided exercises targeting detection, containment, and response workflows.
Course Customization Options
- For a customized training session tailored to your organization's specific incident response procedures or tools, please contact us to arrange it.
Mastering Continuous Threat Exposure Management (CTEM)
28 HoursThis instructor-led, live training in Argentina (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to implement CTEM in their organizations.
By the end of this training, participants will be able to:
- Understand the principles and stages of CTEM.
- Identify and prioritize risks using CTEM methodologies.
- Integrate CTEM practices into existing security protocols.
- Utilize tools and technologies for continuous threat management.
- Develop strategies to validate and improve security measures continuously.
Cyber Emergency Response Team (CERT)
7 HoursThis course explores the management of an incident response team. Given the frequency and complexity of contemporary cyber attacks, the role of the first responder is pivotal, making incident response a critical function for organizations.
As the final line of defense, effective incident detection and response demand robust management processes. Leading an incident response team necessitates specialized skills and expertise.
Cyber Threat Intelligence
35 HoursThis instructor-led, live training in Argentina (online or onsite) is aimed at advanced-level cyber security professionals who wish to understand Cyber Threat Intelligence and learn skills to effectively manage and mitigate cyber threats.
By the end of this training, participants will be able to:
- Understand the fundamentals of Cyber Threat Intelligence (CTI).
- Analyze the current cyber threat landscape.
- Collect and process intelligence data.
- Perform advanced threat analysis.
- Leverage Threat Intelligence Platforms (TIPs) and automate threat intelligence processes.
Fundamentals of Corporate Cyber Warfare
14 HoursThis instructor-led, live training in Argentina (online or onsite) covers the different aspects of enterprise security, from AI to database security. It also includes coverage of the latest tools, processes and mindset needed to protect from attacks.
Ethical Hacker
35 HoursThis course immerses students in an interactive learning environment, demonstrating how to scan, test, exploit, and secure their own systems. The lab-intensive setting provides each participant with in-depth knowledge and practical experience in essential current security systems. Students start by understanding how perimeter defenses operate, then proceed to scan and attack their own networks—ensuring no real-world infrastructure is affected. Learners then explore how attackers escalate privileges and discover the steps necessary to secure a system. The curriculum also covers Intrusion Detection, Policy Creation, Social Engineering, DDoS Attacks, Buffer Overflows, and Virus Creation. Upon completing this intensive five-day class, students will possess a hands-on understanding and practical experience in Ethical Hacking.
The purpose of the Ethical Hacking Training is to:
- Establish and govern minimum standards for credentialing professional information security specialists in ethical hacking measures.
- Inform the public that credentialed individuals meet or exceed these minimum standards.
- Reinforce ethical hacking as a unique and self-regulating profession.
Audience:
This course is ideal for professionals in roles such as, but not limited to:
- Security Engineers
- Security Consultants
- Security Managers
- IT Directors/Managers
- Security Auditors
- IT Systems Administrators
- IT Network Administrators
- Network Architects
- Developers
Certified Lead Ethical Hacker
35 HoursWhy should you attend?
The Certified Lead Ethical Hacker training course enables you to develop the necessary expertise to perform information system penetration tests by applying recognized principles, procedures and penetration testing techniques, in order to identify potential threats on a computer network. During this training course, you will gain the knowledge and skills to manage a penetration testing project or team, as well as plan and perform internal and external pentests, in accordance with various standards such as the Penetration Testing Execution Standard (PTES) and the Open Source Security Testing Methodology Manual (OSSTMM). Moreover, you will also gain a thorough understanding on how to draft reports and countermeasure proposals. Additionally, through practical exercises, you will be able to master penetration testing techniques and acquire the skills needed to manage a pentest team, as well as customer communication and conflict resolution.
The Certified Lead Ethical Hacking training course provides a technical vision of information security through ethical hacking, using common techniques such as information gathering and vulnerability detection, both inside and outside of a business network.
The training is also compatible with the NICE (The National Initiative for Cybersecurity Education) Protect and Defend framework.
After mastering the necessary knowledge and skills in ethical hacking, you can take the exam and apply for the "PECB Certified Lead Ethical Hacker" credential. By holding a PECB Lead Ethical Hacker certificate, you will be able to demonstrate that you have acquired the practical skills for performing and managing penetration tests according to best practices.
Who should attend?
- Individuals interested in IT Security, and particularly in Ethical Hacking, to either learn more about the topic or to start a process of professional reorientation.
- Information security officers and professionals seeking to master ethical hacking and penetration testing techniques.
- Managers or consultants wishing to learn how to control the penetration testing process.
- Auditors wishing to perform and conduct professional penetration tests.
- Persons responsible for maintaining the security of information systems in an organization.
- Technical experts who want to learn how to prepare a pentest.
- Cybersecurity professionals and information security team members.
MasterClass Certified Ethical Hacker Program
28 HoursThe Certified Ethical Hacker certification is a globally recognized cybersecurity credential highly valued in the industry.
This comprehensive program blends theoretical instruction with practical exercises to prepare students for both the CEH certification exam and the CEH Practical Exam. By successfully passing both assessments, candidates earn the prestigious CEH Master credential alongside their CEH certification.
Participants have the flexibility to enhance their package by adding either the CPENT or the CHFI course.
Each student will receive training for the chosen add-on—either the Certified Penetration Testing Professional (CPENT) course or the Computer Hacking Forensic Investigator (CHFI) course—through EC-Council’s online, self-paced, streaming video platform.
CPENT (Pen-test):
This module teaches students how to apply the concepts and tools learned in the CEH program to penetration testing methodologies within a live cyber range environment.
CHFI (Computer Forensics):
This module instructs students on a systematic approach to computer forensics, covering search and seizure procedures, chain-of-custody management, acquisition, preservation, analysis, and reporting of digital evidence.
Course Description
The CEH certification offers a deep dive into the phases of ethical hacking, diverse attack vectors, and preventive countermeasures. It reveals the mindset and malicious tactics of hackers, empowering you to build robust security infrastructures and defend against future threats. Understanding system weaknesses and vulnerabilities enables organizations to strengthen their security controls and minimize incident risks.
CEH is designed to provide a hands-on learning environment and a systematic process across all ethical hacking domains. It gives you the opportunity to demonstrate the knowledge and skills required to achieve the CEH credential. Through this program, you will adopt a fundamentally different perspective on the responsibilities and measures necessary for security.
Who Should Attend
- Law enforcement personnel
- System administrators
- Security officers
- Defense and military personnel
- Legal professionals
- Bankers
- Security professionals
About the Certified Ethical Hacker Master
To earn the CEH Master certification, you must pass the CEH Practical exam. This exam is designed to verify that you can execute the principles taught in the CEH course. It requires you to demonstrate the application of ethical hacking techniques, including threat vector identification, network scanning, OS detection, vulnerability analysis, system hacking, and more.
The CEH Practical Exam does not rely on simulations. Instead, you will tackle challenges in a live cyber range designed to mimic a corporate network using live virtual machines, networks, and applications.
Successfully completing the challenges in the CEH Practical Exam is the next step after attaining the Certified Ethical Hacker (CEH) certification. Passing both the CEH exam and the CEH Practical Exam earns you the additional CEH Master certification.
About the Certified Ethical Hacker Practical
To prove your expertise in ethical hacking, your abilities are tested against real-world challenges in a realistic environment. Using labs and tools, you must complete specific ethical hacking tasks within a time limit, mirroring the pressures of the real world.
The EC-Council CEH (Practical) exam features a complex network that replicates a large organization's real-life infrastructure, including various network systems (such as a DMZ, Firewalls, etc.). You must apply your ethical hacking skills to discover and exploit real-time vulnerabilities while simultaneously auditing the systems.
About CPENT
EC-Council’s Certified Penetration Tester (CPENT) program focuses on penetration testing, teaching you to operate in enterprise network environments that require attack, exploitation, evasion, and defense. If you are accustomed to flat networks, CPENT’s live practice range will elevate your skills by teaching you to pen test IoT and OT systems, write custom exploits, build your own tools, conduct advanced binary exploitation, double pivot to access hidden networks, and customize scripts and exploits to infiltrate the deepest segments of a network.
About CHFI
The Computer Hacking Forensic Investigator (CHFI) course provides a vendor-neutral perspective on the digital forensics discipline. It is a comprehensive curriculum covering major forensic investigation scenarios and enabling students to gain hands-on experience with various forensic techniques and standard tools required to successfully conduct computer forensic investigations.