Under attack?
Advanced programme

Detection engineering

For the people who write the rules and answer for their quality over time. A poorly designed rule does not only cost time: it creates a false impression of coverage.

  • 3 to 4 days
  • Advanced level
  • MITRE ATT&CK
  • Coverage measurement
Who this programme is for

Writing a rule is easy. Making it useful is less so.

Many platforms are weighed down by inherited rules nobody dares switch off, which generate noise and hide what matters. This programme teaches a method for designing, testing, documenting and retiring use cases.

It is aimed at experienced analysts, security engineers and detection leads who want to move from an accumulation mindset to measured coverage.

Prerequisites

Real practice with a SIEM and fluency in its search language. The SOC analyst programme is suitable preparation.

Skills covered

  • Turn a threat into a formalised detection requirement
  • Design a use case and define its success criterion
  • Write a robust correlation rule
  • Test it against validation data
  • Measure and reduce the false positive rate
  • Map coverage by ATT&CK technique
  • Document a rule so someone else can pick it up
  • Decide when a rule has outlived its usefulness
Syllabus

Five modules

ModuleContentFormat
1 · MethodologyFrom threat intelligence to use case: formalisation, detection hypothesis, data required.Lecture and workshop
2 · DesignRule structure, thresholds, time windows, lookup lists, exception handling.Hands-on
3 · ValidationTest datasets, attack replay, measuring detection rate and false positive rate.Hands-on
4 · CoverageMITRE ATT&CK mapping, identifying blind spots, prioritising development.Mapping workshop
5 · Life cycleDocumentation, versioning, periodic review, retirement criteria, detection debt.Lecture and method
Practical information

Organisation

Duration3 to 4 days
AudienceExperienced analysts, security engineers, detection leads
Group size4 to 8 participants
EnvironmentA dedicated lab platform, with validation datasets
Platforms coveredSplunk, Microsoft Sentinel, Elastic Security, OpenText ArcSight, Wazuh
FormatOn site, remotely in a virtual classroom, or a mix of both
DeliverableThe use cases produced during the session are handed over to you, ready to be taken further

A rule catalogue to bring back under control?

We can combine this programme with an audit of your existing use cases, run separately, so that the training then addresses the situations that audit brings to light.