Get in Touch

Course Outline

Foundations of Detection Engineering

  • Essential concepts and job responsibilities
  • The detection engineering lifecycle
  • Primary tools and telemetry origins

Interpreting Log Sources

  • Endpoint logs and event traces
  • Network traffic and flow information
  • Cloud and identity provider logs

Leveraging Threat Intelligence in Detection

  • Categories of threat intelligence
  • Integrating TI to guide detection design
  • Correlating threats with specific log sources

Constructing Effective Detection Rules

  • Rule logic and pattern architectures
  • Distinguishing between behavioral and signature-based detection
  • Utilizing Sigma, Elastic, and SO rules

Alert Tuning and Optimization

  • Reducing false positive noise
  • Iterative refinement of rules
  • Comprehending alert context and threshold settings

Investigative Methodologies

  • Verifying detections
  • Pivoting analysis across multiple data sources
  • Recording findings and investigation details

Implementing Detections Operationally

  • Version control and change management
  • Deploying rules into production environments
  • Monitoring rule efficacy over time

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing techniques
  • Automation potential within detection workflows

Overview and Future Steps

Requirements

  • Foundational knowledge of networking principles
  • Practical experience with operating systems such as Windows or Linux
  • Acquaintance with essential cybersecurity terminology

Target Audience

  • Junior analysts with an interest in security monitoring
  • Newly appointed SOC team members
  • IT specialists transitioning into detection engineering roles
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories