Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Essential concepts and professional responsibilities
  • The detection engineering lifecycle
  • Primary tools and telemetry origins

Log Source Interpretation

  • Endpoint logs and associated event artifacts
  • Network traffic patterns and flow records
  • Cloud platform and identity provider logs

Integrating Threat Intelligence

  • Categories of threat intelligence
  • Utilizing TI to guide detection architecture
  • Correlating threats with appropriate log sources

Constructing Robust Detection Rules

  • Logical structures and pattern recognition in rules
  • Distinguishing between behavioral and signature-based detection
  • Application of Sigma, Elastic, and SO rule frameworks

Alert Refinement and Optimization

  • Strategies for reducing false positives
  • Process of iterative rule improvement
  • Evaluating alert context and threshold settings

Investigative Methodologies

  • Verification of detected threats
  • Executing pivots across multiple data sources
  • Recording findings and maintaining investigation notes

Operational Deployment of Detections

  • Version control and change management practices
  • Rolling out rules to production environments
  • Ongoing monitoring of rule efficacy

Advanced Perspectives for Junior Engineers

  • Alignment with MITRE ATT&CK framework
  • Data standardization and parsing techniques
  • Automation potential within detection workflows

Conclusion and Future Directions

Requirements

  • A foundational grasp of basic networking principles
  • Practical experience operating systems such as Windows or Linux
  • Acquaintance with core cybersecurity vocabulary

Intended Audience

  • Junior analysts with an interest in security monitoring
  • Newly appointed SOC team members
  • IT specialists transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories