Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Basics of Detection Engineering
- Essential concepts and duties
- The detection engineering cycle
- Primary tools and telemetry origins
Recognizing Log Sources
- Endpoint logs and event traces
- Network traffic and flow information
- Cloud and identity provider records
Leveraging Threat Intelligence for Detection
- Categories of threat intelligence
- Applying TI to guide detection design
- Correlating threats with pertinent log sources
Creating Robust Detection Rules
- Rule logic and pattern frameworks
- Identifying behavioral versus signature-based actions
- Utilizing Sigma, Elastic, and SO rules
Alert Tuning and Refinement
- Reducing false positives
- Ongoing rule improvement
- Comprehending alert context and limits
Investigation Strategies
- Verifying detections
- Transitioning between data sources
- Recording findings and investigation details
Implementing Detections Operationally
- Version control and change management
- Releasing rules to production environments
- Tracking rule effectiveness over time
Advanced Topics for Junior Engineers
- Alignment with MITRE ATT&CK
- Data standardization and parsing
- Automation possibilities in detection processes
Conclusion and Future Directions
Requirements
- Grasp of fundamental networking principles
- Hands-on experience with operating systems like Windows or Linux
- Acquaintance with basic cybersecurity vocabulary
Target Audience
- Junior analysts with an interest in security monitoring
- Recently onboarded SOC team members
- IT professionals transitioning into detection engineering
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.