Detection Engineering Professional: hands-on training to simulate attacks, investigate telemetry, and write your own Elastic Security detection rules.
Overview
Syllabus
- simulate real attacker techniques in a live Windows Active Directory lab: RDP abuse, PsExec, WinRM, WMI, persistence, credential access, process injection
- trace those attacks through Windows Event Logs, Sysmon, and EDR/XDR telemetry
- write, tune, and validate custom detection rules in Elastic Security KQL and Sysmon config
- Deploy and configure Elastic Defend, Elastic Security's EDR agent
- apply proactive defense: hardening, mitigation, threat hunting, and full incident response
- use the Elastic Security AI assistant to speed up detection engineering, without trusting it blindly
- think like both attacker and defender, including bypassing your own detection rules to find the gaps before a real adversary does
- Welcome
- What you will find here
- Blue Team / Purple Team Fundamentals
- The Essence of this Course
- Introduction
- Who is a Hacker
- Basic Concepts - Part 1,2
- The CIA Triad
- The DAD Triad
- The Cyber Kill-Chain - Part 1,2
- Threat Actor Types
- Infamous Cyber Attacks
- Attacker's Goals & Desires
- How attackers hide their traces
- The Darknet
- Reconnaissance
- Google Hacking & Dorks
- Port Mapping with Nmap
- AV-EDR Bypass - Part 1,2
- Social Engineering Phishing Web Page
- SSL Stripping - Part 1,2
- Infrastructure Exploitation
- Post Exploitation - Part 1,2
- Remote Brute Force
- Intro
- Types of Malware
- Malware Analysis
- The ATT&CK MITRE Framework
- Atomic Red Team
- The Emotet Usecase - Part 1,2
- Intro
- Basic Concepts
- The Principle of Least Privilege - Part 1,2
- General Security Best Practices
- VLAN Hopping
- More Attack Techniques
- Network Attacks Mitigation Practices
- DDoS Attacks & Mitigations
- Brute Force & Physical Access Attacks
- DNS Zone Transfer Attack & Mitigations
- Credential Dumping & Mitigations
- OS & Network Security
- IR Intro - Part 1,2
- Preparation
- Identification & Analysis - Part 1,2
- Incident Containment - Part 1,2
- Incident Eradication & Recovery
- The Aftermath - What happens after the Incident
- Threat Hunting - Part 1,2,3
- Intro & Log Sources
- Exploring Windows Event Viewer - Part 1,2
- Common Windows Event IDs - Part 1,2
- Analyzing Event ID 4625 Failed Logon - Part 1,2
- Analyzing Event ID 4624 Successful Logon
- Domain Discovery & Lack of Telemetry Data - Part 1,2
- Sysmon Intro - Part 1,2
- Core Sysmon Event IDs & Blind Spots
- Deploying Sysmon
- Detecting Nltest using ProcessCreate Event - Part 1,2
- Detecting the Net command using ProcessCreate Event - Part 1,2
- Detecting DNS Queries - Part 1,2
- Detecting Persistence using the FileCreate event - Part 1,2
- Detecting Persistence using RegistryEvent - Part 1,2
- Detecting Credential Access using ImageLoad - Part 1,2
- Sysmon Events Exclusion
- Detecting the CreateRemoteThread Process Injection
- Intro
- AV vs. EDR vs. XDR vs. SIEM
- Detection Kill-Chain & Process Tree
- Detection Correlation
- Incidents & Alerts Chain of Events
- Elastic Security EDR Overview
- Deploying Elastic Defend - Part 1,2
- Optimizing the Security Policy and Enabling Anti-Tampering
- EDR Telemetry Collection Sanity Check
- Attack & Defense Intro
- RDP Attack Simulation
- RDP Attack Investigation
- RDP Attack Detection - Part 1,2,3
- PSexec Attack Simulation
- PSexec Attack Investigation
- PSexec Attack Detection
- WinRM Attack Simulation
- WinRM Attack Investigation
- WinRM Attack Detection
- Nltest Discovery Simulation
- Nltest Discovery Investigation
- Nltest Discovery Detection
- Net Discovery Simulation
- Net Discovery Investigation
- Net Discovery Detection
- The Emotet Usecase - Detecting PowerShell Attacks
- WMI Attack Simulation
- WMI Attack Investigation
- WMI Attack Detection
- KeyMgr Detection Bypass Red Team Edition - Part 1,2
- Registry Persistence Attack Simulation
- Registry Persistence Attack Investigation
- Registry Persistence Attack Detection
- Service Persistence Attack Simulation
- Service Persistence Attack Investigation
- Service Persistence Attack Detection
- Startup Folder Persistence Attack Simulation
- Startup Folder Persistence Attack Investigation
- Startup Folder Persistence Attack Detection
- Credential Access Techniques
- Process Injection Techniques Attack Simulation
- Process Injection Techniques Attack Investigation & Detection
- AI Assisted Detection Engineering - Part 1,2,3
- Pro Tips
- Attack Simulation and Detection Engineering Practice Labs
- Thank you
- Interesting Windows Folder Paths - Part 1,2
- Interesting Windows Registry Keys
- Online community
- Full Lifetime Access
- Certification
- 14 Day Money-Back
- Installments available