Get in Touch
 Duration 21 hours

Course Outline

Core Principles of Detection Engineering

  • Foundational concepts and role responsibilities
  • The detection engineering lifecycle
  • Essential tools and telemetry sources

Analyzing Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow data
  • Cloud and identity provider logs

Leveraging Threat Intelligence

  • Categories of threat intelligence
  • Utilizing TI to guide detection design
  • Aligning threats with pertinent log sources

Crafting Effective Detection Rules

  • Rule logic and pattern structures
  • Identifying behavioral versus signature-based activity
  • Implementing Sigma, Elastic, and SO rules

Alert Refinement and Optimization

  • Reducing false positives
  • Iterative rule improvement
  • Comprehending alert context and thresholds

Investigation Methodologies

  • Verifying detections
  • Pivoting across various data sources
  • Recording findings and investigative notes

Implementing Detections Operationally

  • Version control and change management
  • Deploying rules to production systems
  • Tracking rule performance over time

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing techniques
  • Automation possibilities in detection workflows

Wrap-Up and Future Directions

Requirements

  • A solid grasp of fundamental networking concepts
  • Practical experience with operating systems such as Windows or Linux
  • Knowledge of core cybersecurity terminology

Target Audience

  • Junior analysts focused on security monitoring
  • Recent additions to SOC teams
  • IT professionals transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories