Tutorialspoint

April Learning Carnival is here, Use code FEST10 for an extra 10% off

Detection Engineering Masterclass: Part 1

person icon Anthony Isherwood

4.4

Detection Engineering Masterclass: Part 1

Detection Engineering Zero to Hero

updated on icon Updated on Apr, 2024

language icon Language - English

person icon Anthony Isherwood

category icon Cyber Security,Anomaly Detection

Lectures -49

Duration -5.5 hours

4.4

price-loader

30-days Money-Back Guarantee

Training 5 or more people ?

Get your team access to 10000+ top Tutorials Point courses anytime, anywhere.

Course Description

Welcome to the Detection Engineering Masterclass: Part 1!


Two Part Course Overview

This course will first teach the theory behind security operations and detection engineering. We’ll then start building out our home lab using VirtualBox and Elastic’s security offering. Then we’ll run through three different attack scenarios, each more complex than the one prior. We’ll make detections off of our attacks, and learn how to document our detections. Next we’ll dive more into coding and Python by writing validation scripts and learning out to interact with Elastic through their API. Wrapping everything up, we’ll host all our detections on GitHub and sync with Elastic through our own GitHub Action automations. As a cherry on top, we’ll have a final section on how to write scripts to gather important metrics and visualizations.


This course takes students from A-Z on the detection engineering lifecycle and technical implementation of a detection engineering architecture.


While this course is marketed as entry level, any prerequisite knowledge will help in the courses learning curve. Familiarity with security operations, searching logs, security analysis, or any related skillset will be helpful (but ultimately not required).


Part One Overview

This is part one of a two part series on Detection Engineering! This course is meant to kickstart anyone interested in security analysis, detection engineering, and security architecture. 


The first part is the meat of the course, where we will go over:

  1. Detection Engineering Theory

  2. Setting Up our Lab

  3. Working with Logging and our SIEM

  4. Running Attack Scenarios to generate logs and create alerts

  5. Learn how to use Atomic Red Team for testing


The second part deals with detection as code philosophies, which will be very Python and GitHub heavy (but don't worry! I'll walk you through everything step by step.)


By the end of this two part course, you'll have a full stack detection engineering architecture. You'll be able to:

  1. Run offensive tests

  2. Review the logs

  3. Make alerts

  4. Save alerts using a standardized template

  5. Enforce template data through code

  6. Programmatically push the alerts to the SIEM

  7. Run periodic metrics off the detection data


The entire course runs ~11 or so hours in length, but should take ~20-40 hours to complete fully. All code written will be available on the course GitHub in case you'd like to skip the Python heavy sections.


Thanks for stopping by! 

Goals

What will you learn in this course:

Part One Overview

This is part one of a two part series on Detection Engineering! This course is meant to kickstart anyone interested in security analysis, detection engineering, and security architecture. 


The first part is the meat of the course, where we will go over:

  1. Detection Engineering Theory

  2. Setting Up our Lab

  3. Working with Logging and our SIEM

  4. Running Attack Scenarios to generate logs and create alerts

  5. Learn how to use Atomic Red Team for testing


The second part deals with detection as code philosophies, which will be very Python and GitHub heavy (but don't worry! I'll walk you through everything step by step.)

Prerequisites

What are the prerequisites for this course?

Requirements

The ability to run 2-3 VMs on a local machine:

  • Ubuntu Linux

  • ParrotOS

  • Windows 11


Minimum Requirements

CPU Cores: 4

RAM: 8gb

Hard Drive Space: 50GB


Recommended Requirements

CPU Cores: 6+

RAM: 16GB+ 

Hard Drive Space: 50GB+


Detection Engineering Masterclass: Part 1

Curriculum

Check out the detailed breakdown of what’s inside the course

Introduction
1 Lectures
  • play icon Introduction 06:59 06:59
Theory
8 Lectures
Tutorialspoint
Lab Setup
8 Lectures
Tutorialspoint
Elastic
10 Lectures
Tutorialspoint
Attack Scenario 1
6 Lectures
Tutorialspoint
Attack Scenario 2
6 Lectures
Tutorialspoint
Attack Scenario 3
5 Lectures
Tutorialspoint
Atomic Red Team
4 Lectures
Tutorialspoint
Conclusion
1 Lectures
Tutorialspoint

Instructor Details

Anthony Isherwood

Anthony Isherwood

e


Course Certificate

Use your certificate to make a career change or to advance in your current career.

sample Tutorialspoint certificate

Our students work
with the Best

Related Video Courses

View More

Annual Membership

Become a valued member of Tutorials Point and enjoy unlimited access to our vast library of top-rated Video Courses

Subscribe now
Annual Membership

Online Certifications

Master prominent technologies at full length and become a valued certified professional.

Explore Now
Online Certifications

Talk to us

1800-202-0515