Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Detection Engineering Fundamentals
- Core concepts and responsibilities
- The detection engineering lifecycle
- Essential tools and telemetry sources
Understanding Log Sources
- Endpoint logs and event artifacts
- Network traffic and flow data
- Logs from cloud and identity providers
Threat Intelligence for Detection
- Types of threat intelligence
- Utilizing TI to inform detection design
- Mapping threats to relevant log sources
Building Effective Detection Rules
- Rule logic and pattern structures
- Detecting behavioral versus signature-based activity
- Employing Sigma, Elastic, and SO rules
Alert Tuning and Optimization
- Reducing false positives
- Iterative rule refinement
- Understanding alert context and thresholds
Investigation Techniques
- Validating detections
- Pivoting across data sources
- Documenting findings and investigation notes
Operationalizing Detections
- Versioning and change management
- Deploying rules to production systems
- Monitoring rule performance over time
Advanced Concepts for Junior Engineers
- MITRE ATT&CK alignment
- Data normalization and parsing
- Automation opportunities in detection workflows
Summary and Next Steps
Requirements
- A foundational understanding of networking concepts
- Experience operating systems such as Windows or Linux
- Familiarity with core cybersecurity terminology
Target Audience
- Junior analysts focused on security monitoring
- Newly appointed SOC team members
- IT professionals transitioning into detection engineering
21 Hours
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.