Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Foundations of Detection Engineering
- Core principles and professional responsibilities
- The end-to-end detection engineering lifecycle
- Essential tools and primary telemetry sources
Analyzing Log Sources
- Endpoint logs and associated event artifacts
- Network traffic patterns and flow data
- Logs from cloud platforms and identity providers
Leveraging Threat Intelligence
- Categorization of threat intelligence data
- Applying threat intelligence to guide detection design
- Correlating threats with specific log sources
Constructing High-Performance Detection Rules
- Rule logic and structural patterns
- Distinguishing between behavioral and signature-based detection
- Utilizing Sigma, Elastic, and Security Onion (SO) rule formats
Refining Alerts and Optimization
- Strategies to minimize false positives
- Processes for iterative rule improvement
- Evaluating alert context and setting appropriate thresholds
Investigation Methodologies
- Validating detection accuracy
- Pivoting across diverse data sources
- Recording findings and detailed investigation notes
Operational Implementation
- Version control and change management practices
- Deploying rules to production environments
- Tracking rule performance over extended periods
Advanced Topics for Junior Engineers
- Alignment with MITRE ATT&CK framework
- Techniques for data normalization and parsing
- Identifying automation potential in detection workflows
Summary and Future Directions
Requirements
- A solid grasp of fundamental networking principles
- Practical experience with operating systems such as Windows or Linux
- Familiarity with core cybersecurity terminology
Target Audience
- Junior analysts focused on security monitoring
- New members of SOC teams
- IT specialists transitioning into detection engineering roles
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.