Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Core principles and professional responsibilities
  • The end-to-end detection engineering lifecycle
  • Essential tools and primary telemetry sources

Analyzing Log Sources

  • Endpoint logs and associated event artifacts
  • Network traffic patterns and flow data
  • Logs from cloud platforms and identity providers

Leveraging Threat Intelligence

  • Categorization of threat intelligence data
  • Applying threat intelligence to guide detection design
  • Correlating threats with specific log sources

Constructing High-Performance Detection Rules

  • Rule logic and structural patterns
  • Distinguishing between behavioral and signature-based detection
  • Utilizing Sigma, Elastic, and Security Onion (SO) rule formats

Refining Alerts and Optimization

  • Strategies to minimize false positives
  • Processes for iterative rule improvement
  • Evaluating alert context and setting appropriate thresholds

Investigation Methodologies

  • Validating detection accuracy
  • Pivoting across diverse data sources
  • Recording findings and detailed investigation notes

Operational Implementation

  • Version control and change management practices
  • Deploying rules to production environments
  • Tracking rule performance over extended periods

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK framework
  • Techniques for data normalization and parsing
  • Identifying automation potential in detection workflows

Summary and Future Directions

Requirements

  • A solid grasp of fundamental networking principles
  • Practical experience with operating systems such as Windows or Linux
  • Familiarity with core cybersecurity terminology

Target Audience

  • Junior analysts focused on security monitoring
  • New members of SOC teams
  • IT specialists transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories