Get in Touch
 Duration 21 hours

Course Outline

The Basics of Detection Engineering

  • Fundamental concepts and professional responsibilities
  • The lifecycle of the detection engineering process
  • Essential tools and telemetry data origins

Grasping Log Data Sources

  • Endpoint logs and event traces
  • Network traffic patterns and flow information
  • Logs from cloud services and identity providers

Leveraging Threat Intelligence for Detection

  • Categories of threat intelligence
  • Applying TI insights to shape detection strategies
  • Linking threats to specific log data streams

Creating High-Impact Detection Rules

  • Logic structures and rule patterns
  • Identifying behavior-based versus signature-based threats
  • Implementing Sigma, Elastic, and SO rule formats

Refining and Optimizing Alerts

  • Reducing the volume of false positives
  • Continuous improvement of rule logic
  • Evaluating alert context and defining appropriate thresholds

Investigative Methodologies

  • Verifying the accuracy of detections
  • Switching between different data sources for deeper analysis
  • Recording investigation outcomes and notes

Implementing Detections in Operations

  • Managing versions and controlling changes
  • Rolling out rules to live production environments
  • Tracking rule effectiveness over time

Advanced Topics for Emerging Engineers

  • Aligning strategies with MITRE ATT&CK
  • Standardizing and parsing data
  • Exploring automation within detection workflows

Wrap-up and Future Directions

Requirements

  • A solid grasp of fundamental networking principles
  • Practical experience operating systems like Windows or Linux
  • Knowledge of essential cybersecurity vocabulary

Target Audience

  • Junior analysts focused on security monitoring
  • Recent additions to SOC teams
  • IT specialists transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories