← All trainingCourse in Guardian Foundry

Detection Engineering Challenges

Analyze Windows and Sysmon event logs and write Sigma rules for suspicious behavior. Work through detection challenges involving reconnaissance, encoded commands, persistence and credential attacks.

What you’ll practice

  • Identify evidence of suspicious activity in Windows and Sysmon logs.
  • Write Sigma rules that express detection logic for the observed behavior.
  • Map the detected techniques to MITRE ATT&CK.

Topics

  • Detection engineering
  • Windows
  • Threat intelligence

Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.

Talk to Rob or Anthony

Plan your team’s training.

Tell us how many people you’re training, their experience levels, and what they need to practice. We’ll discuss a training plan, learner support, and the reporting your team needs.

info@leveleffect.com
Email the team

We aim to respond within 1–2 business days.