Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Essentials of Detection Engineering
- Fundamental concepts and key responsibilities
- The complete detection engineering lifecycle
- Essential tools and primary telemetry origins
Comprehending Log Origins
- Endpoint logs and relevant event artifacts
- Network traffic patterns and flow data
- Logs from cloud services and identity providers
Applying Threat Intelligence to Detections
- Categorization of threat intelligence types
- Leveraging TI to guide detection architecture
- Aligning threats with appropriate log sources
Creating Robust Detection Rules
- Logic structures and rule patterns
- Distinguishing between behavioral and signature-based activities
- Implementation of Sigma, Elastic, and SO rules
Refining and Optimizing Alerts
- Strategies to minimize false positives
- Continuous iterative improvement of rules
- Contextual understanding and threshold management for alerts
Investigative Methodologies
- Verification of detection triggers
- Correlating data across multiple sources
- Recording findings and investigation documentation
Implementing Detections Operationally
- Version control and change management practices
- Rolling out rules to live production systems
- Ongoing performance monitoring of deployed rules
Advanced Insights for Junior Engineers
- Alignment with MITRE ATT&CK frameworks
- Processes for data normalization and parsing
- Exploring automation possibilities in detection workflows
Recap and Future Pathways
Requirements
- A solid grasp of fundamental networking principles
- Practical experience operating systems such as Windows or Linux
- Knowledge of core cybersecurity terminology
Target Audience
- Junior analysts keen on security monitoring roles
- Recently onboarded SOC team members
- IT specialists transitioning into detection engineering
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.