Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Core Principles of Detection Engineering
- Essential concepts and professional responsibilities
- The lifecycle of detection engineering
- Primary tools and telemetry sources
Analyzing Log Sources
- Endpoint logs and event artifacts
- Network traffic and flow data
- Cloud and identity provider logs
Leveraging Threat Intelligence for Detection
- Categorization of threat intelligence
- Applying TI to guide detection design
- Correlating threats with specific log sources
Crafting Effective Detection Rules
- Logic structures and rule patterns
- Distinguishing between behavioral and signature-based detection
- Utilization of Sigma, Elastic, and SO rules
Alert Tuning and Refinement
- Strategies for minimizing false positives
- Iterative improvement of rules
- Comprehending alert context and threshold settings
Investigative Methodologies
- Verification of detections
- Pivoting analysis across multiple data sources
- Recording findings and investigation documentation
Deployment of Detections
- Version control and change management
- Implementation of rules in production environments
- Long-term monitoring of rule performance
Advanced Topics for Junior Engineers
- Alignment with MITRE ATT&CK
- Data normalization and parsing techniques
- Identifying automation potential in detection workflows
Conclusion and Future Pathways
Requirements
- A foundational grasp of basic networking concepts
- Practical experience with operating systems such as Windows or Linux
- Acquaintance with core cybersecurity terminology
Target Audience
- Entry-level analysts focused on security monitoring
- Newly joined SOC team members
- IT professionals transitioning into detection engineering roles
Testimonials (1)
Clarity and pace of explanations