00 - Detection Engineering as a Discipline: Scripts to Pipelines
Introduction to modern detection engineering: evolution from isolated scripts to CI/CD pipelines for security rules.
Detection engineering: SIEM/SOAR, sigma rules, threat detection, incident response automation, malware analysis e costruzione di pipeline di sicurezza defensive.
Introduction to modern detection engineering: evolution from isolated scripts to CI/CD pipelines for security rules.
Writing Sigma rules for universal detection: YAML syntax, logsource mapping and automatic conversion for Splunk, Elastic and Sentinel.
Implementing Detection-as-Code: version control for rules, CI/CD pipeline, automated testing and SIEM deployment.
Integrating MITRE ATT&CK into workflow: automatic coverage mapping, gap identification and detection prioritization.
Writing SOAR playbooks in Python: incident response automation, enrichment, containment and action orchestration.
Building a threat intelligence processor: STIX/TAXII feed ingestion, IOC parsing, enrichment and correlation.
ML models for behavioral anomaly detection on logs: feature engineering, isolation forest, autoencoder and baseline modeling.
Using LLMs to generate Sigma rules: prompt engineering, automatic validation, testing and AI-assisted iteration.
Alert triage automation with graph analysis: alert correlation, noise reduction, prioritization and MTTD reduction.
Unit testing for detection rules: test framework, synthetic log generation, red team validation and coverage metrics.
As-tu lu tous les articles ? Vérifie ce que tu as appris avec le quiz de la série.