← All trainingCourse in Guardian Foundry
Detection Engineering Challenges
Analyze Windows and Sysmon event logs and write Sigma rules for suspicious behavior. Work through detection challenges involving reconnaissance, encoded commands, persistence and credential attacks.
What you’ll practice
- Identify evidence of suspicious activity in Windows and Sysmon logs.
- Write Sigma rules that express detection logic for the observed behavior.
- Map the detected techniques to MITRE ATT&CK.
Topics
- Detection engineering
- Windows
- Threat intelligence
Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.