Detection engineering
For the people who write the rules and answer for their quality over time. A poorly designed rule does not only cost time: it creates a false impression of coverage.
Writing a rule is easy. Making it useful is less so.
Many platforms are weighed down by inherited rules nobody dares switch off, which generate noise and hide what matters. This programme teaches a method for designing, testing, documenting and retiring use cases.
It is aimed at experienced analysts, security engineers and detection leads who want to move from an accumulation mindset to measured coverage.
Real practice with a SIEM and fluency in its search language. The SOC analyst programme is suitable preparation.
Skills covered
- Turn a threat into a formalised detection requirement
- Design a use case and define its success criterion
- Write a robust correlation rule
- Test it against validation data
- Measure and reduce the false positive rate
- Map coverage by ATT&CK technique
- Document a rule so someone else can pick it up
- Decide when a rule has outlived its usefulness
Five modules
| Module | Content | Format |
|---|---|---|
| 1 · Methodology | From threat intelligence to use case: formalisation, detection hypothesis, data required. | Lecture and workshop |
| 2 · Design | Rule structure, thresholds, time windows, lookup lists, exception handling. | Hands-on |
| 3 · Validation | Test datasets, attack replay, measuring detection rate and false positive rate. | Hands-on |
| 4 · Coverage | MITRE ATT&CK mapping, identifying blind spots, prioritising development. | Mapping workshop |
| 5 · Life cycle | Documentation, versioning, periodic review, retirement criteria, detection debt. | Lecture and method |
Organisation
| Duration | 3 to 4 days |
| Audience | Experienced analysts, security engineers, detection leads |
| Group size | 4 to 8 participants |
| Environment | A dedicated lab platform, with validation datasets |
| Platforms covered | Splunk, Microsoft Sentinel, Elastic Security, OpenText ArcSight, Wazuh |
| Format | On site, remotely in a virtual classroom, or a mix of both |
| Deliverable | The use cases produced during the session are handed over to you, ready to be taken further |
A rule catalogue to bring back under control?
We can combine this programme with an audit of your existing use cases, run separately, so that the training then addresses the situations that audit brings to light.