Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Core Principles of Detection Engineering
- Foundational concepts and role responsibilities
- The detection engineering lifecycle
- Essential tools and telemetry sources
Analyzing Log Sources
- Endpoint logs and event artifacts
- Network traffic and flow data
- Cloud and identity provider logs
Leveraging Threat Intelligence
- Categories of threat intelligence
- Utilizing TI to guide detection design
- Aligning threats with pertinent log sources
Crafting Effective Detection Rules
- Rule logic and pattern structures
- Identifying behavioral versus signature-based activity
- Implementing Sigma, Elastic, and SO rules
Alert Refinement and Optimization
- Reducing false positives
- Iterative rule improvement
- Comprehending alert context and thresholds
Investigation Methodologies
- Verifying detections
- Pivoting across various data sources
- Recording findings and investigative notes
Implementing Detections Operationally
- Version control and change management
- Deploying rules to production systems
- Tracking rule performance over time
Advanced Topics for Junior Engineers
- Alignment with MITRE ATT&CK
- Data normalization and parsing techniques
- Automation possibilities in detection workflows
Wrap-Up and Future Directions
Requirements
- A solid grasp of fundamental networking concepts
- Practical experience with operating systems such as Windows or Linux
- Knowledge of core cybersecurity terminology
Target Audience
- Junior analysts focused on security monitoring
- Recent additions to SOC teams
- IT professionals transitioning into detection engineering roles
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.