Get in Touch
 Duration 21 hours

Course Outline

Basics of Detection Engineering

  • Fundamental concepts and role responsibilities
  • The full detection engineering lifecycle
  • Essential tools and telemetry origins

Comprehending Log Sources

  • Endpoint logs and event data artifacts
  • Network traffic and flow metrics
  • Cloud services and identity provider records

Leveraging Threat Intelligence

  • Categories of threat intelligence
  • Applying intelligence to guide detection design
  • Correlating threats with specific log sources

Crafting High-Impact Detection Rules

  • Rule logic and pattern frameworks
  • Distinguishing between behavioral and signature-based detections
  • Utilizing Sigma, Elastic, and SO rule formats

Refining and Optimizing Alerts

  • Reducing the volume of false positives
  • Continuous improvement of rule definitions
  • Grasping alert context and sensitivity thresholds

Investigation Methodologies

  • Verifying detection accuracy
  • Cross-referencing multiple data sources
  • Recording findings and investigation details

Implementing Detections Operationally

  • Version control and change management practices
  • Rolling out rules to production environments
  • Tracking rule effectiveness over time

Advanced Topics for Entry-Level Engineers

  • Alignment with the MITRE ATT&CK framework
  • Data standardization and parsing techniques
  • Opportunities for automation in detection processes

Wrap-up and Future Directions

Requirements

  • Basic knowledge of networking principles
  • Practical experience with operating systems like Windows or Linux
  • Acquaintance with core cybersecurity terminology

Target Audience

  • Junior analysts focused on security monitoring
  • Newly joined members of SOC teams
  • IT specialists transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories