Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Key principles and role responsibilities
  • The detection engineering lifecycle
  • Primary tools and telemetry sources

Understanding Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow data
  • Logs from cloud services and identity providers

Threat Intelligence for Detection

  • Varieties of threat intelligence
  • Leveraging TI to guide detection design
  • Mapping threats to corresponding log sources

Building Effective Detection Rules

  • Rule logic and pattern structures
  • Distinguishing behavioral from signature-based activity
  • Implementing Sigma, Elastic, and SO rules

Alert Tuning and Optimization

  • Reducing false positives
  • Iterative refinement of rules
  • Comprehending alert context and thresholds

Investigation Techniques

  • Validating detections
  • Pivoting across various data sources
  • Documenting findings and investigative notes

Operationalizing Detections

  • Version control and change management
  • Deploying rules to production systems
  • Monitoring rule performance over time

Advanced Concepts for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing
  • Automation opportunities in detection workflows

Summary and Next Steps

Requirements

  • A solid grasp of fundamental networking principles
  • Practical experience with operating systems such as Windows or Linux
  • Knowledge of basic cybersecurity terminology

Target Audience

  • Junior analysts focused on security monitoring
  • New members joining a SOC team
  • IT specialists transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories