Summary
This chapter continued from the previous chapter in introducing the practical implementation of the first phases of the detection engineering life cycle, following the identification of detection requirements, this time focused on behavior-based detections. We discussed how to take a detection requirement associated with a tool or TTP and perform research into how the requirement can be met.
After performing research into each requirement, we performed hands-on exercises to show how the information gathered can be used to implement detections in your lab environment, including performing additional logging configurations to capture the events needed.
Now that we’ve seen how the detection engineering life cycle can get you from a detection requirement to an implemented detection, Chapter 8 will look at how we can document detections in a way that will allow for easier tracking and organization. Additionally, we will discuss how detection pipelines and detection...