Get in Touch
 Duration 21 hours

Course Outline

Core Foundations of Detection Engineering

  • Fundamental concepts and professional responsibilities
  • The end-to-end detection engineering lifecycle
  • Essential tools and telemetry origins

Decoding Log Sources

  • Endpoint logs and event-generated artifacts
  • Network traffic patterns and flow data
  • Logs from cloud services and identity providers

Leveraging Threat Intelligence for Detection

  • Categories of threat intelligence
  • Utilizing TI to guide detection architecture
  • Aligning threats with pertinent log sources

Constructing High-Quality Detection Rules

  • Rule logic and structural patterns
  • Identifying behavioral versus signature-based anomalies
  • Implementing Sigma, Elastic, and SO rules

Tuning and Optimizing Alerts

  • Strategies for reducing false positives
  • Continuous refinement of rules
  • Comprehending alert context and threshold settings

Advanced Investigation Methods

  • Verification of detections
  • Cross-referencing data across multiple sources
  • Recording findings and investigation documentation

Implementing Detections Operationally

  • Version control and change management processes
  • Rolling out rules to production environments
  • Tracking rule performance over extended periods

Progressive Concepts for Junior Engineers

  • Alignment with MITRE ATT&CK frameworks
  • Data standardization and parsing techniques
  • Identifying automation potential in detection pipelines

Recap and Future Directions

Requirements

  • Basic knowledge of networking principles
  • Practical experience operating systems like Windows or Linux
  • Acquaintance with core cybersecurity terminology

Target Audience

  • Junior analysts with an interest in security monitoring
  • Newly appointed SOC team members
  • IT professionals transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories