Back to all modules

Detection Engineering

Detection Engineering icon

Understand various threat detection methodologies, rule syntax and tools, and learn how to apply them in a SOC environment.

In this module, we shall be looking at the concepts of detection engineering, including a usable lifecycle, rule writing and testing, orchestration and automation. We’ll dive deeper into how to write detection rules using Sigma and how Windows Event alerts can be triggered using an EDR called Aurora. Additionally, we shall cover the basic concepts of Security Orchestration, Automation and Response (SOAR) and look at how you can implement playbooks and workflows in different scenarios.

Detection Engineering icon

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Module tree diagram

We use cookies to ensure you get the best user experience. For more information contact us.

Read more