Advanced Intrusion Detection by Infosec
6h 4mAdvanced2025-08-26
Authors

Infosec Institute
Course details
Learn the methodology behind intrusion detection and craft detection rules and logic. This course begins with an overview of intrusion detection and then dives into the data required to build various detection use cases and various open-source tools and frameworks for building and tuning your detections. Throughout the course, review the various aspects and frameworks that comprise intrusion detection techniques (network- and host-based) and explore real world use-cases and examples of detection methodology. At the end of this course, you should have the necessary skills to craft meaningful detections that can aid in identifying malicious activity within your organization's environment.
Concepts
Introduction
- Introduction to advanced intrusion detection
Intrusion Detection Techniques and Methods
- What is intrusion detection
- Detection methodology
- Types of intrusion detection
- Intrusion detection requirements
Home Lab Setup
- Detection lab overview
- Lab use cases
- Tools and technology
- Documentation
- Intro to building a security lab
- VirtualBox installation
- Set up and provision Security Onion
Network-Based vs. Host-Based Detection
- Network-based vs. host-based
- IDS and IPS rules
- Wazuh (HIDS overview)
Anomaly Detection
- Anomaly detection overview
- Anomaly detection techniques
- Issues with anomaly detection
The ATT&CK Matrix and Threat Intel
- What is the ATT&CK Matrix
- Adversary tactics, techniques, and procedures (TTPs)
- Leveraging threat intelligence
Data Management
- Data management overview
- Data collection methods
- Data mover example
- Data science and cybersecurity
Tactical Data
- Detection life cycle
- Data dictionary and data models
- Crafting detections
Advanced Detection through Deception Technology
- What is cyber deception
- Honeypot usage