Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Key principles and professional responsibilities
  • The detection engineering lifecycle
  • Essential tools and telemetry origins

Comprehending Log Sources

  • Endpoint logs and event records
  • Network traffic and flow information
  • Cloud and identity provider logs

Leveraging Threat Intelligence for Detection

  • Categories of threat intelligence
  • Applying threat intelligence to guide detection design
  • Correlating threats with specific log sources

Crafting Effective Detection Rules

  • Rule logic and pattern architecture
  • Identifying behavioral versus signature-based activities
  • Utilizing Sigma, Elastic, and SO rules

Alert Tuning and Refinement

  • Reducing false positives
  • Continuous rule improvement
  • Interpreting alert context and thresholds

Investigation Methodologies

  • Verifying detections
  • Connecting data across multiple sources
  • Recording findings and investigative notes

Implementing Detections Operationally

  • Version control and change management
  • Rolling out rules to production environments
  • Tracking rule effectiveness over time

Advanced Concepts for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing techniques
  • Automation potential in detection workflows

Wrap-up and Future Directions

Requirements

  • Proficiency with fundamental networking principles
  • Practical experience operating systems like Windows or Linux
  • Basic knowledge of cybersecurity terminology

Target Audience

  • Junior analysts focusing on security monitoring
  • New members joining SOC teams
  • IT specialists transitioning into detection engineering roles

Testimonials (2)

Related Categories