Get in Touch
 Duration 21 hours

Course Outline

Essentials of Detection Engineering

  • Fundamental concepts and key responsibilities
  • The complete detection engineering lifecycle
  • Essential tools and primary telemetry origins

Comprehending Log Origins

  • Endpoint logs and relevant event artifacts
  • Network traffic patterns and flow data
  • Logs from cloud services and identity providers

Applying Threat Intelligence to Detections

  • Categorization of threat intelligence types
  • Leveraging TI to guide detection architecture
  • Aligning threats with appropriate log sources

Creating Robust Detection Rules

  • Logic structures and rule patterns
  • Distinguishing between behavioral and signature-based activities
  • Implementation of Sigma, Elastic, and SO rules

Refining and Optimizing Alerts

  • Strategies to minimize false positives
  • Continuous iterative improvement of rules
  • Contextual understanding and threshold management for alerts

Investigative Methodologies

  • Verification of detection triggers
  • Correlating data across multiple sources
  • Recording findings and investigation documentation

Implementing Detections Operationally

  • Version control and change management practices
  • Rolling out rules to live production systems
  • Ongoing performance monitoring of deployed rules

Advanced Insights for Junior Engineers

  • Alignment with MITRE ATT&CK frameworks
  • Processes for data normalization and parsing
  • Exploring automation possibilities in detection workflows

Recap and Future Pathways

Requirements

  • A solid grasp of fundamental networking principles
  • Practical experience operating systems such as Windows or Linux
  • Knowledge of core cybersecurity terminology

Target Audience

  • Junior analysts keen on security monitoring roles
  • Recently onboarded SOC team members
  • IT specialists transitioning into detection engineering

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories