Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Core principles and professional responsibilities
  • The lifecycle of detection engineering
  • Essential tools and telemetry origins

Comprehending Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow information
  • Logs from cloud services and identity providers

Leveraging Threat Intelligence for Detection

  • Categories of threat intelligence
  • Incorporating TI into detection strategy
  • Aligning threats with specific log sources

Creating High-Impact Detection Rules

  • Rule logic and pattern architecture
  • Distinguishing between behavioral and signature-based detection
  • Utilizing Sigma, Elastic, and SO rules

Optimizing Alerts and Tuning

  • Reducing false positive rates
  • Continuous refinement of rules
  • Evaluating alert context and threshold settings

Investigative Methodologies

  • Verifying detection outcomes
  • Correlating data across multiple sources
  • Recording findings and investigative notes

Deploying Detections Operationally

  • Managing versions and changes
  • Implementing rules in live production environments
  • Tracking rule performance metrics over time

Advanced Concepts for Entry-Level Engineers

  • Alignment with MITRE ATT&CK framework
  • Data normalization and parsing techniques
  • Opportunities for automation in detection processes

Recap and Future Directions

Requirements

  • Basic knowledge of networking principles
  • Proficiency with operating systems like Windows or Linux
  • Knowledge of core cybersecurity terminology

Target Audience

  • Junior analysts focused on security monitoring
  • Recently hired SOC team members
  • IT specialists transitioning into detection engineering

Number of participants


Price per participant

Testimonials (2)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories