Skip to main content

Defensive Engineering in the Enterprise

February 1st, 2nd & 3rd
Intermediate

Defensive Engineering in the Enterprise

Description

This training offers a comprehensive, modern approach to defensive engineering for an enterprise, shifting from our previous attack-class-focused curriculum to a broader defensive skillset. This includes detection strategy, telemetry management, analytics, and automation. You will learn to prioritize detections by combining risk, likelihood, and detectability with a deep understanding of their operational environment. The training will then guide you through the entire lifecycle of development, tuning, maintenance, and potential deprecation. The training is very hands-on and based on our experience supporting many detection and response teams in large multinationals. We dive into log ingestion decision-making (what to collect, how to process, and how to track data completeness), the internals of EDR telemetry, how it gathers data, covering Event Tracing for Windows, and addressing telemetry gaps. The advanced detection engineering topic is a substantial part of the curriculum, covering the research and design of realistic and current attacks in an enterprise. You will execute several attacks and research the generated telemetry to build detections based on your findings. Additionally, we will cover implementation and differentiate between scheduled, near-real-time, and threat hunt-based approaches, including baseline development best practices. Automation is addressed through playbooks and AI-based agentic workflows, while dashboarding and reporting modules cover cost management, detection and data health monitoring, performance metrics, and tuning suggestions. This training equips you with the tools and frameworks needed to build, maintain, and evolve a proactive security program.

Course Level

Intermediate

Course Requirements

Laptop with RDP and internet connection

Key takeaways

Participants gain practical guidance on crafting performant KQL queries, leveraging graphs (including OpenCypher) for enrichment, attack path visualization, and incident correlation, as well as developing alert enrichments (attack paths, local context, identity data) and risk-based scoring. Automation is addressed through playbooks and AI-based agentic workflows, while dashboarding and reporting modules cover cost management, detection and data health monitoring, performance metrics, and tuning suggestions. This training equips you with the tools and frameworks needed to build, maintain, and evolve a proactive security program.

Speaker

Suggested sessions