Get in Touch
 Duration 21 hours

Course Outline

Core Principles of Detection Engineering

  • Essential concepts and professional responsibilities
  • The lifecycle of detection engineering
  • Primary tools and telemetry sources

Analyzing Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow data
  • Cloud and identity provider logs

Leveraging Threat Intelligence for Detection

  • Categorization of threat intelligence
  • Applying TI to guide detection design
  • Correlating threats with specific log sources

Crafting Effective Detection Rules

  • Logic structures and rule patterns
  • Distinguishing between behavioral and signature-based detection
  • Utilization of Sigma, Elastic, and SO rules

Alert Tuning and Refinement

  • Strategies for minimizing false positives
  • Iterative improvement of rules
  • Comprehending alert context and threshold settings

Investigative Methodologies

  • Verification of detections
  • Pivoting analysis across multiple data sources
  • Recording findings and investigation documentation

Deployment of Detections

  • Version control and change management
  • Implementation of rules in production environments
  • Long-term monitoring of rule performance

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing techniques
  • Identifying automation potential in detection workflows

Conclusion and Future Pathways

Requirements

  • A foundational grasp of basic networking concepts
  • Practical experience with operating systems such as Windows or Linux
  • Acquaintance with core cybersecurity terminology

Target Audience

  • Entry-level analysts focused on security monitoring
  • Newly joined SOC team members
  • IT professionals transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories