← All trainingCourse in Guardian Foundry

Intro to Detection Engineering

Write endpoint detections with Sigma and YARA, then test them through adversary emulation. Connect detection logic to the behavior and artifacts produced by an attack simulation.

What you’ll practice

  • Write Sigma rules for endpoint behavior and YARA rules for malware artifacts.
  • Run introductory adversary emulation exercises in the training environment.
  • Validate detection rules against the activity produced by those exercises.

Topics

  • Detection engineering

Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.

Talk to Rob or Anthony

Plan your team’s training.

Tell us how many people you’re training, their experience levels, and what they need to practice. We’ll discuss a training plan, learner support, and the reporting your team needs.

info@leveleffect.com
Email the team

We aim to respond within 1–2 business days.