Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
The Basics of Detection Engineering
- Fundamental concepts and professional responsibilities
- The lifecycle of the detection engineering process
- Essential tools and telemetry data origins
Grasping Log Data Sources
- Endpoint logs and event traces
- Network traffic patterns and flow information
- Logs from cloud services and identity providers
Leveraging Threat Intelligence for Detection
- Categories of threat intelligence
- Applying TI insights to shape detection strategies
- Linking threats to specific log data streams
Creating High-Impact Detection Rules
- Logic structures and rule patterns
- Identifying behavior-based versus signature-based threats
- Implementing Sigma, Elastic, and SO rule formats
Refining and Optimizing Alerts
- Reducing the volume of false positives
- Continuous improvement of rule logic
- Evaluating alert context and defining appropriate thresholds
Investigative Methodologies
- Verifying the accuracy of detections
- Switching between different data sources for deeper analysis
- Recording investigation outcomes and notes
Implementing Detections in Operations
- Managing versions and controlling changes
- Rolling out rules to live production environments
- Tracking rule effectiveness over time
Advanced Topics for Emerging Engineers
- Aligning strategies with MITRE ATT&CK
- Standardizing and parsing data
- Exploring automation within detection workflows
Wrap-up and Future Directions
Requirements
- A solid grasp of fundamental networking principles
- Practical experience operating systems like Windows or Linux
- Knowledge of essential cybersecurity vocabulary
Target Audience
- Junior analysts focused on security monitoring
- Recent additions to SOC teams
- IT specialists transitioning into detection engineering roles
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
instructor's benevolence
Pierre Do Huu - L'assurance maladie
Course - MITRE ATT&CK
Machine Translated