{"id":406,"date":"2025-11-18T22:04:00","date_gmt":"2025-11-18T22:04:00","guid":{"rendered":"https:\/\/zombierollz.blog\/?p=406"},"modified":"2025-11-18T18:04:37","modified_gmt":"2025-11-18T18:04:37","slug":"intro-to-detection-engineering","status":"publish","type":"post","link":"https:\/\/zombierollz.blog\/?p=406","title":{"rendered":"Intro to Detection Engineering"},"content":{"rendered":"\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-a58be4567e1367f6c0f587c8762a0372 wp-block-paragraph\">Room link: https:\/\/tryhackme.com\/room\/introtodetectionengineering<br>Created by: tryhackme, SecurityNomad<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-0a38e84fb05548a2f345a7c5962f93f5 wp-block-paragraph\">While this is not part of the SOC Level 1 path, it was recommended at the beginning of the room &#8220;Introduction to SOAR&#8221;: https:\/\/tryhackme.com\/room\/soar. I skimmed over the Tasks before I decided that it would be good to complete the room fully, as it seems like a good one.<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-94b6933160e487ca40bbfe5107cffffe wp-block-paragraph\">&#8220;Detection engineering is an important role and task for a security analyst. It involves developing processes that will guide you as an analyst to identify threats, detect them through rules and processes, and fine-tune the process as the landscape changes.&#8221;<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-b387875f255743f5a0d8dcdc5909f22f wp-block-paragraph\">In task 2, &#8220;What is Detection Engineering?&#8221;, THM brings up two categories when it comes to threat detection: Environment-based detection, &#8220;focuses on looking at changes in an environment based on configurations and baseline activities that have been defined. Within this detection, we have Configuration detection and Modelling.&#8221; and Threat-based detection, &#8220;focuses on elements associated with an adversary\u2019s activity, such as tactics, tools and artefacts that would identify their actions. Under this, we have Indicators and Threat Behavior detections.&#8221;<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-66328d9ef4e1c63773e1ca7b234f683d wp-block-paragraph\">The room covers a good amount of detail when it comes to these as well as Configuration Detection, Modelling, Indicator Detection, Threat Behavior Detection, and Detection as Code.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"228\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-105944-1024x228.png\" alt=\"\" class=\"wp-image-407\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-105944-1024x228.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-105944-300x67.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-105944-768x171.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-105944.png 1352w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"280\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-110229-1024x280.png\" alt=\"\" class=\"wp-image-408\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-110229-1024x280.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-110229-300x82.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-110229-768x210.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-110229.png 1387w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-4973e4f64ad65c7d90adba2eb0eacfed wp-block-paragraph\">In Task 3, Detection Engineering Methodologies, THM covers the importance of Gap Analysis and reactive\/proactive approaches. The room goes into baseline creations, log collection, rule writing, deployment, automation, and tuning. When it comes to rule writing, THM links to three other rooms we could look at later: https:\/\/tryhackme.com\/room\/snort, https:\/\/tryhackme.com\/room\/yara, and https:\/\/tryhackme.com\/room\/sigma.<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-7b4dfddb7ce99381eb1a4f5cb9381e43 wp-block-paragraph\">In Task 4, a refresher is in store. It covers a little about the MITRE ATT&amp;CK and CAR frameworks, Pyramid of Pain, and Cyber Kill Chain.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"250\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-112532-1024x250.png\" alt=\"\" class=\"wp-image-409\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-112532-1024x250.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-112532-300x73.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-112532-768x187.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-112532.png 1374w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-9cbfcbdb273f05e11e94d50a4968c679 wp-block-paragraph\">Task 5, &#8220;Detection Engineering Frameworks 2,&#8221; is more detailed than previous tasks and links to github page: https:\/\/github.com\/palantir\/alerting-detection-strategy-framework by Palantir. The room also goes over Ryan Stillions&#8217; &#8220;Detection Maturity Level (DML)&#8221; which came out in 2014.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"599\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115159-1024x599.png\" alt=\"\" class=\"wp-image-410\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115159-1024x599.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115159-300x175.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115159-768x449.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115159.png 1330w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"618\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115909-1024x618.png\" alt=\"\" class=\"wp-image-411\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115909-1024x618.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115909-300x181.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115909-768x464.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-115909.png 1304w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-b4ec1ee04c8cf95269c9bb64f3ccbbfb wp-block-paragraph\">In the final task, &#8220;Detection Detective&#8221;, we are given a scenario of &#8220;THM\u00a0is seeking to establish a detection engineering process to detect changes made to privileged and administrative groups and accounts in their\u00a0<strong>Active Directory<\/strong>. As a detection analyst, you have been tasked with developing a strategy based on a set of questions. Each question comes with one correct answer; therefore, it is up to you to identify and select it. You will have three attempts to complete the exercise before it resets.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"881\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-120234-1024x881.png\" alt=\"\" class=\"wp-image-413\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-120234-1024x881.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-120234-300x258.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-120234-768x660.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-15-120234.png 1092w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Room link: https:\/\/tryhackme.com\/room\/introtodetectionengineeringCreated by: tryhackme, SecurityNomad While this is not part of the SOC Level 1 path, it was recommended at the beginning of the room &#8220;Introduction to SOAR&#8221;: https:\/\/tryhackme.com\/room\/soar. I skimmed over the Tasks before I decided that it would be good to complete the room fully, as it seems like a good one. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-406","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"blocksy_meta":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/406","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=406"}],"version-history":[{"count":2,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/406\/revisions"}],"predecessor-version":[{"id":414,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/406\/revisions\/414"}],"wp:attachment":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=406"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=406"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=406"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}