Get in Touch
 Duration 21 hours

Course Outline

Basics of Detection Engineering

  • Essential concepts and duties
  • The detection engineering cycle
  • Primary tools and telemetry origins

Recognizing Log Sources

  • Endpoint logs and event traces
  • Network traffic and flow information
  • Cloud and identity provider records

Leveraging Threat Intelligence for Detection

  • Categories of threat intelligence
  • Applying TI to guide detection design
  • Correlating threats with pertinent log sources

Creating Robust Detection Rules

  • Rule logic and pattern frameworks
  • Identifying behavioral versus signature-based actions
  • Utilizing Sigma, Elastic, and SO rules

Alert Tuning and Refinement

  • Reducing false positives
  • Ongoing rule improvement
  • Comprehending alert context and limits

Investigation Strategies

  • Verifying detections
  • Transitioning between data sources
  • Recording findings and investigation details

Implementing Detections Operationally

  • Version control and change management
  • Releasing rules to production environments
  • Tracking rule effectiveness over time

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data standardization and parsing
  • Automation possibilities in detection processes

Conclusion and Future Directions

Requirements

  • Grasp of fundamental networking principles
  • Hands-on experience with operating systems like Windows or Linux
  • Acquaintance with basic cybersecurity vocabulary

Target Audience

  • Junior analysts with an interest in security monitoring
  • Recently onboarded SOC team members
  • IT professionals transitioning into detection engineering

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories