Defensive Engineering in the Enterprise
February 1st, 2nd & 3rd
Intermediate
Speakers:
Description
This training offers a comprehensive, modern approach to defensive engineering for an enterprise, shifting from our previous attack-class-focused curriculum to a broader defensive skillset. This includes detection strategy, telemetry management, analytics, and automation. You will learn to prioritize detections by combining risk, likelihood, and detectability with a deep understanding of their operational environment. The training will then guide you through the entire lifecycle of development, tuning, maintenance, and potential deprecation. The training is very hands-on and based on our experience supporting many detection and response teams in large multinationals.
We dive into log ingestion decision-making (what to collect, how to process, and how to track data completeness), the internals of EDR telemetry, how it gathers data, covering Event Tracing for Windows, and addressing telemetry gaps.
The advanced detection engineering topic is a substantial part of the curriculum, covering the research and design of realistic and current attacks in an enterprise. You will execute several attacks and research the generated telemetry to build detections based on your findings. Additionally, we will cover implementation and differentiate between scheduled, near-real-time, and threat hunt-based approaches, including baseline development best practices.
Automation is addressed through playbooks and AI-based agentic workflows, while dashboarding and reporting modules cover cost management, detection and data health monitoring, performance metrics, and tuning suggestions. This training equips you with the tools and frameworks needed to build, maintain, and evolve a proactive security program.
Course Level
Intermediate
Course Requirements
Laptop with RDP and internet connection
Key takeaways
Participants gain practical guidance on crafting performant KQL queries, leveraging graphs (including OpenCypher) for enrichment, attack path visualization, and incident correlation, as well as developing alert enrichments (attack paths, local context, identity data) and risk-based scoring.
Automation is addressed through playbooks and AI-based agentic workflows, while dashboarding and reporting modules cover cost management, detection and data health monitoring, performance metrics, and tuning suggestions. This training equips you with the tools and frameworks needed to build, maintain, and evolve a proactive security program.



















