Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Core principles and professional responsibilities
  • The detection engineering lifecycle
  • Essential tools and telemetry origins

Exploring Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow information
  • Cloud and identity provider logs

Applying Threat Intelligence

  • Categories of threat intelligence
  • Incorporating TI into detection design
  • Aligning threats with corresponding log sources

Constructing Effective Detection Rules

  • Rule logic and pattern architecture
  • Distinguishing between behavioral and signature-based activity
  • Implementing Sigma, Elastic, and SO rules

Alert Tuning and Optimization

  • Reducing false positives
  • Iterative refinement of rules
  • Comprehending alert context and thresholds

Investigation Methodologies

  • Verifying detections
  • Pivoting across multiple data sources
  • Documenting findings and investigation notes

Operational Implementation

  • Version control and change management
  • Deploying rules to production environments
  • Monitoring rule effectiveness over time

Advanced Perspectives for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing
  • Automation potential in detection workflows

Conclusion and Next Steps

Requirements

  • Understanding of fundamental networking concepts
  • Hands-on experience with operating systems such as Windows or Linux
  • Knowledge of basic cybersecurity terminology

Target Audience

  • Junior analysts with an interest in security monitoring
  • Recent additions to SOC teams
  • IT specialists transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories