Book Image

Practical Threat Detection Engineering

By : Megan Roddie, Jason Deyalsingh, Gary J. Katz
5 (2)
Book Image

Practical Threat Detection Engineering

5 (2)
By: Megan Roddie, Jason Deyalsingh, Gary J. Katz

Overview of this book

Threat validation is an indispensable component of every security detection program, ensuring a healthy detection pipeline. This comprehensive detection engineering guide will serve as an introduction for those who are new to detection validation, providing valuable guidelines to swiftly bring you up to speed. The book will show you how to apply the supplied frameworks to assess, test, and validate your detection program. It covers the entire life cycle of a detection, from creation to validation, with the help of real-world examples. Featuring hands-on tutorials and projects, this guide will enable you to confidently validate the detections in your security program. This book serves as your guide to building a career in detection engineering, highlighting the essential skills and knowledge vital for detection engineers in today's landscape. By the end of this book, you’ll have developed the skills necessary to test your security detection program and strengthen your organization’s security measures.
Table of Contents (20 chapters)
1
Part 1: Introduction to Detection Engineering
5
Part 2: Detection Creation
11
Part 3: Detection Validation
14
Part 4: Metrics and Management
16
Part 5: Detection Engineering as a Career

Exercise – understanding your organization’s detection requirement sources

The following questions will assist you in identifying how each of the concepts applies to your organization. If you do not work in a role or company that provides you with the information to answer these questions, choose a fictional company to use with this book. As this book progress, questions like these will help reinforce the concept that certain aspects of your DE program will be heavily influenced by organization-specific characteristics. Being able to take information about an organization and understand how it affects detection development is an important DE skill:

  1. Review the detection requirement sources listed in the chapter. Which of these apply to your organization?
  2. Do your current processes enable these stakeholders to easily submit new requirements? How can your processes be improved to increase participation?

By answering these questions regarding your organization...