Get in Touch
 Duration 21 hours

Course Outline

Core Principles of Detection Engineering

  • Essential concepts and roles
  • The detection engineering lifecycle
  • Primary tools and telemetry inputs

Identifying Log Sources

  • Endpoint logs and event records
  • Network traffic and flow records
  • Cloud and identity provider logs

Leveraging Threat Intelligence for Detection

  • Categorizations of threat intelligence
  • Applying TI to guide detection design
  • Correlating threats with specific log sources

Creating High-Impact Detection Rules

  • Rule logic and pattern frameworks
  • Distinguishing between behavioral and signature-based threats
  • Utilizing Sigma, Elastic, and SO rules

Alert Calibration and Enhancement

  • Reducing false positives
  • Continuous rule refinement
  • Interpreting alert context and thresholds

Investigative Techniques

  • Verifying detections
  • Tracing incidents across multiple data sources
  • Recording findings and investigation details

Implementing Detections in Production

  • Version control and change management
  • Rolling out rules to production environments
  • Tracking rule performance over time

Advanced Insights for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing techniques
  • Opportunities for automation in detection processes

Conclusion and Future Directions

Requirements

  • Basic knowledge of networking principles
  • Practical experience with operating systems such as Windows or Linux
  • Understanding of core cybersecurity terminology

Target Audience

  • Junior analysts with an interest in security monitoring
  • Newly joined SOC team members
  • IT professionals transitioning into detection engineering roles

Testimonials (2)

Upcoming Courses

Related Categories