Course Outline

Foundations of Detection Engineering

  • Core concepts and responsibilities
  • The detection engineering lifecycle
  • Key tools and telemetry sources

Understanding Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow data
  • Cloud and identity provider logs

Threat Intelligence for Detection

  • Types of threat intelligence
  • Using TI to inform detection design
  • Mapping threats to relevant log sources

Building Effective Detection Rules

  • Rule logic and pattern structures
  • Detecting behavioral vs signature-based activity
  • Using Sigma, Elastic, and SO rules

Alert Tuning and Optimization

  • Minimizing false positives
  • Iterative rule refinement
  • Understanding alert context and thresholds

Investigation Techniques

  • Validating detections
  • Pivoting across data sources
  • Documenting findings and investigation notes

Operationalizing Detections

  • Versioning and change management
  • Deploying rules to production systems
  • Monitoring rule performance over time

Advanced Concepts for Junior Engineers

  • MITRE ATT&CK alignment
  • Data normalization and parsing
  • Automation opportunities in detection workflows

Summary and Next Steps

Requirements

  • An understanding of basic networking concepts
  • Experience with using operating systems such as Windows or Linux
  • Familiarity with fundamental cybersecurity terminology

Audience

  • Junior analysts interested in security monitoring
  • New SOC team members
  • IT professionals moving into detection engineering
 21 Hours

Delivery Options

Private Group Training

Our identity is rooted in delivering exactly what our clients need.

  • Pre-course call with your trainer
  • Customisation of the learning experience to achieve your goals -
    • Bespoke outlines
    • Practical hands-on exercises containing data / scenarios recognisable to the learners
  • Training scheduled on a date of your choice
  • Delivered online, onsite/classroom or hybrid by experts sharing real world experience

Private Group Prices RRP from €6840 online delivery, based on a group of 2 delegates, €2160 per additional delegate (excludes any certification / exam costs). We recommend a maximum group size of 12 for most learning events.

Contact us for an exact quote and to hear our latest promotions


Public Training

Please see our public courses

Testimonials (4)

Provisonal Upcoming Courses (Contact Us For More Information)

Related Categories