← All trainingLearning path in Guardian Foundry

Detection Engineering & Threat Hunting: Windows & CDETH

Build and test YARA, Snort and Sigma detections, manage detection code in GitHub and use adversary emulation to assess coverage. Progress through practical detection challenges to the Certified Detection Engineer & Threat Hunter (CDETH) assessment.

A learning path guides you through related courses in a set order. It can also include assessments to check your progress.

What you’ll practice

  • Use regular expressions and write YARA, Snort and Sigma detection rules.
  • Manage detections with version control, documentation and CI/CD workflows.
  • Emulate adversary techniques and map detection coverage to MITRE ATT&CK.
  • Test and tune detection logic using observed behavior and false-positive evidence.

Topics

  • Detection engineering
  • Threat hunting
  • Windows

Counts include distinct published activities in this learning path. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.

Talk to Rob or Anthony

Plan your team’s training.

Tell us how many people you’re training, their experience levels, and what they need to practice. We’ll discuss a training plan, learner support, and the reporting your team needs.

info@leveleffect.com
Email the team

We aim to respond within 1–2 business days.