
Detection Engineering can be a minefield of technical and logistical challenges, but in this workshop, you’ll learn the fundamentals within a fully functional SIEM.
Course Length: 4 Hours
Includes a Certificate of Completion
Next scheduled date:
Description
Detection Engineering can be a minefield of technical and logistical challenges, but in this workshop, you’ll learn the fundamentals within a fully functional SIEM.
From writing custom threat detections using a structured and scientific process to test-firing them yourself, you’ll gain hands-on experience that bridges the gap between theory and practice. By the end of this workshop, you will not only have a strong foundation in detection engineering knowledge but also the practical skills to build effective and high-fidelity detections from the ground up.
-
System Requirements
- A computer
-
Student Requirements
- A MetaCTF account - labs will be performed via MetaCTF Cloud Labs
- An email ready to use to sign up for an Elastic Cloud free trial (you can't have used that email for an Elastic Cloud trial previously)
Syllabus
-
- Elastic Search Basics
-
- SIEM Detection Engineering Basics
-
- The Detection Engineering Process
-
- Testing Threat Detections
-
- Setting Your Analysts Up for Success
FAQ
SOC engineers, managers, analysts, or those wanting to work in a SOC
Anyone wanting to learn the basic of how to write threat detections
Introductory. A basic level of fundamental knowledge is helpful but is not strictly necessary.
About the Instructor
Hayden Covington
"Security Engineer, Triathlete, and Analytics Addict"Bio
Hayden Covington is a Senior Analyst in Black Hills Information Security’s SOC where he specializes in training, quality assurance, detection engineering, and investigative analysis. With a previous background as a SOC analyst for a US naval contractor, Hayden has extensive experience in Digital Forensics and Incident Response (DFIR), Security Orchestration, Automation, and Response (SOAR), and insider threat.
Related products
-
Kevin TackettLiveOD12 Hrs
Practical OWASP TOP 10
View Course This product has multiple variants. The options may be chosen on the product page -
Andrew KrugLiveOD16 Hrs
Securing the Cloud: Foundations
View Course This product has multiple variants. The options may be chosen on the product page -
Multiple InstructorsLive16 Hrs
Security Defense and Detection TTX
View Course -
John StrandLiveOD16 Hrs
SOC Core Skills
View Course This product has multiple variants. The options may be chosen on the product page

