Get in Touch
 Duration 21 hours

Course Outline

Basics of Detection Engineering

  • Core principles and key responsibilities
  • The detection engineering lifecycle
  • Essential tools and telemetry data sources

Identifying Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow data
  • Logs from cloud services and identity providers

Applying Threat Intelligence to Detection

  • Categories of threat intelligence
  • Leveraging TI to guide detection design
  • Aligning threats with specific log sources

Creating Robust Detection Rules

  • Rule logic and pattern frameworks
  • Distinguishing between behavioral and signature-based activity
  • Utilizing Sigma, Elastic, and SO rules

Tuning and Optimizing Alerts

  • Reducing false positives
  • Iterative refinement of rules
  • Comprehending alert context and thresholds

Investigation Methodologies

  • Verifying detections
  • Pivoting across various data sources
  • Documenting insights and investigation records

Implementing Detections Operationally

  • Version control and change management
  • Deploying rules to production environments
  • Tracking rule performance over time

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data standardization and parsing
  • Automation possibilities in detection workflows

Wrap-Up and Future Pathways

Requirements

  • Knowledge of fundamental networking principles
  • Practical experience with operating systems like Windows or Linux
  • Basic familiarity with core cybersecurity terminology

Target Audience

  • Entry-level analysts focused on security monitoring
  • New members of SOC teams
  • IT professionals transitioning into detection engineering roles

Testimonials (2)

Related Categories