##.o0ΓXΓ0o.| DΝΜ½eΝΜ½aΝΜ½tΝΜ½hΝΜ½ RΝΜ½eΝΜ½sΝΜ½oΝΜ½uΝΜ½rΝΜ½cΝΜ½eΝΜ½sΝΜ½ |.o0ΓXΓ0o.##:
- Regular Expressions (Regex)
- Research - Detection and Response
-
π― Detection Engineering
-
π£ Phishing
-
Regular Expressions - Beginner
-
πΉπ Threat Hunt
| Domain | Core Skills |
|---|---|
| π― Detection Engineering | Detection logic, tuning, validation, Detection-as-Code |
| π΅οΈ Threat Hunting | Hypothesis-driven hunting, behavioral analysis |
| π§ Threat Intelligence | IOC/TTP analysis, adversary research |
| π¬ Digital Forensics | Windows artifacts, DFIR, investigation |
| πͺ Windows Security | Internals, processes, persistence, execution |
| π Query Engineering | KQL, Splunk, Regex |
| βοΈ Automation | PowerShell, scripting, CI/CD |
| π Telemetry | Logs, events, endpoint/network data |
| π§© Frameworks | MITRE ATT&CK, Diamond Model, Pyramid of Pain |
| π‘οΈ Security Operations | Detection, investigation, response |
1. Build the Fundamentals β TryHackMe Detection Engineering β MITRE ATT&CK β Pyramid of Pain β Diamond Model
2. Start Building Detections β Antisyphon SOC Detection Engineering β TCM Security Detection Engineering for Beginners
3. Build Supporting Skills β PowerShell β Regex β Splunk β KQL
4. Understand the Operating System β 13Cubed Digital Forensics β SANS Forensics
5. Develop Hunting & Intelligence Skills β Intel 471 β Huntress research
6. Advance Your Detection Engineering β SpecterOps Funnel of Fidelity β Level Effect β Death of Windows
π― Goal: Move beyond simply writing detection rules. Develop the ability to understand operating systems, execute and observe attacks, identify useful telemetry, investigate adversary behavior, and translate that knowledge into high-fidelity detections.
Build the technical depth to understand what happened, the analytical skill to determine why it matters, and the engineering discipline to turn that knowledge into high-fidelity detections.
A curated collection of hands-on labs, courses, videos, and readings for developing practical Detection Engineering, Threat Hunting, Digital Forensics, and Security Operations skills.
A practical progression from fundamentals to advanced Detection Engineering:
βββββββββββββββββββββββββ
β FUNDAMENTALS β
β β
β MITRE ATT&CK β
β Pyramid of Pain β
β Diamond Model β
βββββββββββββ¬ββββββββββββ
β
βΌ
βββββββββββββββββββββββββ
β DETECTION DEVELOPMENTβ
β β
β Detection Engineering β
β Detection-as-Code β
β Detection Logic β
βββββββββββββ¬ββββββββββββ
β
βΌ
βββββββββββββββββββββββββ
β QUERY & AUTOMATION β
β β
β KQL β
β Splunk β
β Regex β
β PowerShell β
βββββββββββββ¬ββββββββββββ
β
βΌ
βββββββββββββββββββββββββ
β OS & TELEMETRY β
β β
β Windows Internals β
β Digital Forensics β
β Security Artifacts β
βββββββββββββ¬ββββββββββββ
β
βΌ
βββββββββββββββββββββββββ
β THREAT HUNTING β
β β
β Hypothesis Developmentβ
β Adversary Behavior β
β Threat Intelligence β
βββββββββββββ¬ββββββββββββ
β
βΌ
βββββββββββββββββββββββββ
β ADVANCED DETECTION β
β β
β Detection Fidelity β
β Detection-as-Code β
β CI/CD β
β Continuous Tuning β
βββββββββββββββββββββββββ
Don't just learn how to write detection rules. Learn how to understand the adversary, the operating system, the telemetry, and the investigation process that makes a detection valuable.
The objective is to develop the ability to:
Understand the Attack
β Execute / Emulate the Technique
β Observe the Telemetry
β Identify Relevant Artifacts
β Develop a Detection
β Validate the Detection
β Tune for Fidelity
β Operationalize
β Hunt for Related Activity
β Generate Intelligence
β Improve the Detection
This creates a continuous feedback loop between Threat Intelligence β Threat Hunting β Detection Engineering β Incident Response β Intelligence.
βββββββββββββββββββββββ
β THREAT INTELLIGENCE β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β THREAT HUNTING β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β DETECTION ENGINEERINGβ
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β INCIDENT RESPONSE β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β NEW INTELLIGENCE β
ββββββββββββ¬βββββββββββ
β
ββββββββββββββββΊ β»οΈ Recycle Phase/Loop β»οΈ
Core Philosophy:
Intelligence drives hypotheses. Hypotheses drive hunts. Hunts generate telemetry. Telemetry drives detections. Detections generate investigations. Investigations produce intelligence.
| Resource | Focus | Level |
|---|---|---|
| Antisyphon Training β SOC Detection Engineering Crash Course | SOC detection engineering, lab simulation, VM-based exercises | π’ Easy β π‘ Moderate |
| TryHackMe β Detection Engineering | Detection engineering fundamentals, MITRE ATT&CK, Pyramid of Pain, Diamond Model | π’ Beginner |
| TCM Security β Detection Engineering for Beginners | Build a detection lab, execute attacks, and develop detections from observed activity | π‘ Moderate |
| Level Effect β Course Options | Advanced Windows security, detection, and threat hunting concepts | π’ Easy β π‘ Moderate |
PowerShell Quick Course β YouTube
Build foundational PowerShell skills for Windows administration, investigation, automation, and detection development.
Lame Creations β Regex & Splunk Guides
Useful material for developing regex skills and working with Splunk searches and detection logic.
Hands-on training for learning Kusto Query Language (KQL) and applying query skills to security investigations and threat hunting.
Excellent resource for understanding Windows internals, digital forensics, artifacts, and investigative techniques.
Understanding how an operating system worksβand what traces activity leaves behindβis critical for developing effective detections.
Additional lectures, presentations, and technical content covering digital forensics, incident response, and investigative methodologies.
Huntress β Security Research & Threat Intelligence
Ongoing research and write-ups covering threat actors, malware, incidents, adversary techniques, and practical security operations.
β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β