Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Foundations of Detection Engineering
- Essential concepts and professional responsibilities
- The detection engineering lifecycle
- Primary tools and telemetry origins
Log Source Interpretation
- Endpoint logs and associated event artifacts
- Network traffic patterns and flow records
- Cloud platform and identity provider logs
Integrating Threat Intelligence
- Categories of threat intelligence
- Utilizing TI to guide detection architecture
- Correlating threats with appropriate log sources
Constructing Robust Detection Rules
- Logical structures and pattern recognition in rules
- Distinguishing between behavioral and signature-based detection
- Application of Sigma, Elastic, and SO rule frameworks
Alert Refinement and Optimization
- Strategies for reducing false positives
- Process of iterative rule improvement
- Evaluating alert context and threshold settings
Investigative Methodologies
- Verification of detected threats
- Executing pivots across multiple data sources
- Recording findings and maintaining investigation notes
Operational Deployment of Detections
- Version control and change management practices
- Rolling out rules to production environments
- Ongoing monitoring of rule efficacy
Advanced Perspectives for Junior Engineers
- Alignment with MITRE ATT&CK framework
- Data standardization and parsing techniques
- Automation potential within detection workflows
Conclusion and Future Directions
Requirements
- A foundational grasp of basic networking principles
- Practical experience operating systems such as Windows or Linux
- Acquaintance with core cybersecurity vocabulary
Intended Audience
- Junior analysts with an interest in security monitoring
- Newly appointed SOC team members
- IT specialists transitioning into detection engineering roles
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.