Cursusaanbod

Foundations of Detection Engineering

  • Core concepts and responsibilities
  • The detection engineering lifecycle
  • Key tools and telemetry sources

Understanding Log Sources

  • Endpoint logs and event artifacts
  • Network traffic and flow data
  • Cloud and identity provider logs

Threat Intelligence for Detection

  • Types of threat intelligence
  • Using TI to inform detection design
  • Mapping threats to relevant log sources

Building Effective Detection Rules

  • Rule logic and pattern structures
  • Detecting behavioral vs signature-based activity
  • Using Sigma, Elastic, and SO rules

Alert Tuning and Optimization

  • Minimizing false positives
  • Iterative rule refinement
  • Understanding alert context and thresholds

Investigation Techniques

  • Validating detections
  • Pivoting across data sources
  • Documenting findings and investigation notes

Operationalizing Detections

  • Versioning and change management
  • Deploying rules to production systems
  • Monitoring rule performance over time

Advanced Concepts for Junior Engineers

  • MITRE ATT&CK alignment
  • Data normalization and parsing
  • Automation opportunities in detection workflows

Summary and Next Steps

Vereisten

  • An understanding of basic networking concepts
  • Experience with using operating systems such as Windows or Linux
  • Familiarity with fundamental cybersecurity terminology

Audience

  • Junior analysts interested in security monitoring
  • New SOC team members
  • IT professionals moving into detection engineering
 21 Uren

Leveringsopties

PRIVÉGROEPSTRAINING

Onze identiteit draait om het leveren van precies wat onze klanten nodig hebben.

  • Pre-cursusgesprek met uw trainer
  • Aanpassing van de leerervaring om uw doelen te bereiken -
    • Op maat gemaakte overzichten
    • Praktische, praktische oefeningen met gegevens / scenario's die herkenbaar zijn voor de cursisten
  • Training gepland op een datum naar keuze
  • Gegeven online, op locatie/klaslokaal of hybride door experts die ervaring uit de echte wereld delen

Private Group Prices RRP from €6840 online delivery, based on a group of 2 delegates, €2160 per additional delegate (excludes any certification / exam costs). We recommend a maximum group size of 12 for most learning events.

Neem contact met ons op voor een exacte offerte en om onze laatste promoties te horen


OPENBARE TRAINING

Kijk op onze public courses

Reviews (4)

Voorlopige Aankomende Cursussen

Gerelateerde categorieën