دوره Applied Network Defense | Detection Engineering with Sigma

Detection Engineering with Sigma will teach you how to write and tune Sigma rules to find evil in logs using real-world examples that take you through the detection engineering process. We’ll dissect real Sigma detection rules focused on finding a variety of malicious activity in diverse log sources. Once you have a good handle on these components, you’ll start writing and tuning your own rules in a series of case studies. In some case studies, I’ll describe a detection gap and you’ll write a rule on your own before I show you how I tackled the problem myself. In other scenarios, you’ll write or modify a rule on your own and submit it to me for feedback. In this course, you are never alone! I will be with you 100% of the way to help you understand the structure of Sigma rules, how to get from idea to finished rule, and best practices for writing resilient rules.

Syllabus

  1. Course Introduction

  2. Lab Toolkit Virtual Machine

  3. Sigma Fundamentals

  4. Case Study 1 – Windows Event Logs

  5. Case Study 2 – Zeek Logs

  6. Case Study 3 – Sysmon Logs

  7. Case Study 4 – AWS CloudTrail Logs

  8. Sigma In Production

  9. Final Challenge

  10. Course Conclusion

Applied Network Defense | Detection Engineering with Sigma