← All trainingCourse in Guardian Foundry
Intro to Detection Engineering
Write endpoint detections with Sigma and YARA, then test them through adversary emulation. Connect detection logic to the behavior and artifacts produced by an attack simulation.
What you’ll practice
- Write Sigma rules for endpoint behavior and YARA rules for malware artifacts.
- Run introductory adversary emulation exercises in the training environment.
- Validate detection rules against the activity produced by those exercises.
Topics
- Detection engineering
Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.