Get in Touch
 Duration 21 hours

Course Outline

Foundations of Detection Engineering

  • Essential concepts and professional responsibilities
  • The complete detection engineering lifecycle
  • Primary tools and telemetry origin points

Understanding Log Sources

  • Endpoint logs and related event artifacts
  • Network traffic patterns and flow data
  • Logs from cloud platforms and identity providers

Threat Intelligence for Detection

  • Categories of threat intelligence data
  • Integrating threat intel to guide detection design
  • Correlating threats with specific log sources

Building Effective Detection Rules

  • Rule logic and structural patterns
  • Identifying behavioral versus signature-based threats
  • Implementing Sigma, Elastic, and SO rule formats

Alert Tuning and Optimization

  • Strategies for minimizing false positives
  • Iterative processes for rule refinement
  • Evaluating alert context and setting appropriate thresholds

Investigation Techniques

  • Methods for validating detection triggers
  • Pivoting across multiple data sources
  • Documenting investigative findings and notes

Operationalizing Detections

  • Managing versioning and changes
  • Rolling out rules to production environments
  • Tracking rule performance over time

Advanced Concepts for Junior Engineers

  • Alignment with MITRE ATT&CK frameworks
  • Data normalization and parsing techniques
  • Identifying automation opportunities in detection workflows

Summary and Next Steps

Requirements

  • A foundational grasp of basic networking principles
  • Practical experience operating Windows or Linux systems
  • Knowledge of core cybersecurity terminology

Intended Audience

  • Junior analysts with an interest in security monitoring
  • Newly onboarded SOC team members
  • IT professionals transitioning into detection engineering roles

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories