Part 2: Detection Creation
Part 2 dives into more technical aspects of detection engineering, focusing on the creation of detections. First, we’ll understand the importance of data sources, how to identify relevant data sources, and the challenges you may face. We’ll then discuss how we can create, investigate, and triage detection requirements. With an understanding of the early steps of the detection engineering life cycle, we can move on to learning how to develop detections for both static and behavior indicators. To wrap up this part, you’ll learn more about the procedural side of things, including how to document detections and automate the development and deployment process.
This section has the following chapters:
- Chapter 4, Detection Data Sources
- Chapter 5, Investigating Detection Requirements
- Chapter 6, Developing Detections Using Indicators of Compromise
- Chapter 7, Developing Detections Using Behavioral Indicators
- Chapter 8...