Get in Touch
 Duration 21 hours

Course Outline

Basics of Detection Engineering

  • Foundational concepts and role responsibilities
  • The detection engineering lifecycle
  • Essential tools and telemetry inputs

Exploring Log Sources

  • Endpoint logs and event traces
  • Network traffic and flow information
  • Cloud and identity provider logs

Leveraging Threat Intelligence for Detection

  • Categorizations of threat intelligence
  • Utilizing intelligence to guide detection architecture
  • Correlating threats with specific log sources

Creating Robust Detection Rules

  • Rule logic and structural patterns
  • Identifying behavioral versus signature-based actions
  • Implementation of Sigma, Elastic, and SO rules

Refining and Optimizing Alerts

  • Reduction of false positives
  • Continuous improvement of rules
  • Comprehension of alert context and threshold settings

Investigation Methodologies

  • Verifying detection accuracy
  • Cross-referencing multiple data sources
  • Recording findings and investigative notes

Implementing Detections in Operations

  • Version control and change management
  • Deployment of rules to production environments
  • Long-term performance monitoring of rules

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK framework
  • Data standardization and parsing
  • Opportunities for automation in detection processes

Conclusion and Future Steps

Requirements

  • A grasp of fundamental networking principles
  • Proficiency in operating systems such as Windows or Linux
  • Knowledge of core cybersecurity terminology

Target Audience

  • Entry-level analysts focused on security monitoring
  • Newly joined SOC team members
  • IT specialists transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories