Get in Touch
 Duration 21 hours

Course Outline

The Basics of Detection Engineering

  • Core principles and key responsibilities
  • The full cycle of detection engineering
  • Essential tools and sources of telemetry

Grasping Log Sources

  • Endpoint logs and related event artifacts
  • Network traffic patterns and flow data
  • Logs from cloud services and identity providers

Integrating Threat Intelligence

  • Various categories of threat intelligence
  • Utilizing TI to guide detection design
  • Connecting threats to pertinent log sources

Crafting Robust Detection Rules

  • Rule logic and structural patterns
  • Distinguishing between behavioral and signature-based detection
  • Applying Sigma, Elastic, and SO rules

Refining and Optimizing Alerts

  • Reducing the occurrence of false positives
  • Continuous refinement of rules
  • Comprehending alert context and threshold settings

Investigation Methodologies

  • Verifying detection validity
  • Pivoting between various data sources
  • Recording findings and investigation notes

Implementing Detections Operationally

  • Managing versions and changes
  • Deploying rules to production environments
  • Tracking rule performance over time

Advanced Topics for Junior Engineers

  • Alignment with MITRE ATT&CK
  • Data normalization and parsing techniques
  • Opportunities for automation in detection processes

Wrap-up and Future Directions

Requirements

  • A solid grasp of fundamental networking concepts
  • Practical experience with operating systems like Windows or Linux
  • Knowledge of basic cybersecurity terminology

Target Audience

  • Junior analysts keen on security monitoring
  • New members joining SOC teams
  • IT professionals transitioning into detection engineering

Testimonials (2)

Related Categories