← All trainingLearning path in Guardian Foundry
Detection Engineering & Threat Hunting: Windows & CDETH
Build and test YARA, Snort and Sigma detections, manage detection code in GitHub and use adversary emulation to assess coverage. Progress through practical detection challenges to the Certified Detection Engineer & Threat Hunter (CDETH) assessment.
A learning path guides you through related courses in a set order. It can also include assessments to check your progress.
What you’ll practice
- Use regular expressions and write YARA, Snort and Sigma detection rules.
- Manage detections with version control, documentation and CI/CD workflows.
- Emulate adversary techniques and map detection coverage to MITRE ATT&CK.
- Test and tune detection logic using observed behavior and false-positive evidence.
Topics
- Detection engineering
- Threat hunting
- Windows
Counts include distinct published activities in this learning path. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.