Get in Touch

Course Outline

Basics of Detection Engineering

  • Fundamental concepts and key responsibilities
  • The detection engineering life cycle
  • Essential tools and sources of telemetry

Navigating Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow information
  • Logs from cloud platforms and identity providers

Applying Threat Intelligence

  • Categories of threat intelligence
  • Utilizing TI to guide detection design
  • Aligning threats with specific log sources

Creating Robust Detection Rules

  • Rule logic and structural patterns
  • Distinguishing between behavioral and signature-based activities
  • Implementing Sigma, Elastic, and SO rules

Alert Refinement and Optimization

  • Reducing the number of false positives
  • Continuous refinement of rules
  • Comprehending alert context and threshold settings

Investigation Methodologies

  • Verifying detection alerts
  • Tracing issues across multiple data sources
  • Recording findings and investigation notes

Implementing Detections Operationally

  • Version control and change management practices
  • Rolling out rules to production environments
  • Tracking rule performance over time

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Normalizing and parsing data
  • Identifying automation potential in detection workflows

Conclusions and Future Paths

Requirements

  • A solid grasp of fundamental networking concepts
  • Practical experience with operating systems like Windows or Linux
  • Knowledge of basic cybersecurity terminology

Target Audience

  • Entry-level analysts with an interest in security monitoring
  • Recently joined SOC team members
  • IT specialists transitioning into detection engineering roles
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories