Security Operations · Intermediate

Detection Engineering

Turn what an investigation learns into tested, version-controlled detections: write Sigma rules, test them positively and negatively, tune false positives, and run them on a lab-local Wazuh manager.

About this course

A SOC analyst who has worked an incident knows what *should* have been caught. Detection engineering is the discipline of turning that knowledge into detection content a team can maintain, measure and retire — not a rule typed into a console and forgotten, but code with tests, review, coverage and a change history. You work on `soc01`, an Ubuntu 24.04 machine that carries the SOC analyst toolkit (auditd, fail2ban, nginx and the ULC-006 synthetic generator) plus a single-node **Wazuh manager**, the **Sigma** detection-as-code toolchain (`sigma-cli`, pySigma and a SQLite backend), and an offline copy of the MITRE ATT&CK and D3FEND data. Everything you investigate is **synthetic**, generated on your own machine from documentation-range addresses; no production log, no customer data and no live target is ever involved. Across ten lessons you learn the detection lifecycle; how to normalise three disagreeing log families into one queryable event stream; how to write a Sigma rule whose logsource, detection, condition, level, tags and false positives pass `sigma check`; how to convert rules to queries with a processing pipeline and see exactly what your backend does and does not support; how to test a rule so it fires on the behaviour and stays silent on a clean day; how to measure and tune false positives with a written rationale; how to keep rules as code with stable ids, an ATT&CK coverage matrix, a peer-review checklist and a fail-closed CI gate; and how to run the same detections continuously on a host and on a Wazuh manager, promoting a rule through a change record with a rollback. The final project hands you an unseen incident bundle and asks for a complete detection pack — rules, pipeline, tests, a false-positive report, a coverage matrix, a passing CI gate and a rollout note — graded against a rubric and automated lab checks that run your rules against held-back synthetic samples.

Content time
17 h 45 min
Lessons
10
Certificate
Yes
on completion
Choose a career path

Lesson 1 is free. Enroll in a career path to access its full courses.

Lesson 1 is a free preview — read it without an account.

Security Operations — the kind of infrastructure this course is practised on

Outline

Lessons

10 lessons · 17 h 45 min
  1. Lesson 1: From analyst to detection engineerFree preview

    What detection engineering is, the lifecycle every detection moves through, and the telemetry you will build detections from.

    1 h 15 min
  2. Lesson 2: Normalising telemetry into one event stream

    Turn three log families that disagree on time and field names into one UTC SQLite table a rule can query once and run everywhere.

    1 h 50 min
  3. Lesson 3: Anatomy of a Sigma rule

    Write a portable, vendor-neutral detection in Sigma — title, logsource, detection, condition, level, tags and false positives — and check it against the specification.

    1 h 50 min
  4. Lesson 4: Pipelines and conversion — from rule to query

    Write a pySigma pipeline that maps portable rules onto your schema, convert rules to SQL, and learn exactly what the SQLite backend supports and what it does not.

    2 h
  5. Lesson 5: Positive and negative fixtures

    A rule is only real when it fires where it should and nowhere else. Write positive and negative fixtures and run every rule like CI, across seeds.

    1 h 50 min
  6. Lesson 6: Measuring and tuning false positives

    Add a benign administrator-noise day, measure each rule's false positives against it, and tune by filter with a written rationale — never by silently raising a threshold.

    1 h 40 min
  7. Lesson 7: The rule repository

    Keep detections as code — a repository layout, stable ids and status, a peer-review checklist, and an ATT&CK coverage matrix generated from the rules themselves.

    1 h 40 min
  8. Lesson 8: CI for detections

    Build a fail-closed CI gate that runs syntax, policy, tests and coverage on every change, install it as a pre-push hook, and prove it blocks a rule with no negative fixture.

    1 h 40 min
  9. Lesson 9: Continuous detection on a running platform

    Deploy a detection to a lab-local Wazuh manager through a scoped change, test it with wazuh-logtest, and run a self-test on a timer so a broken rule set is caught automatically.

    2 h
  10. Lesson 10: Wazuh rules, decoders and the detection lifecycle

    Translate a second detection to Wazuh, understand decoders and the ATT&CK version gap between tools, and promote a rule through a change record with a rollback and a retirement plan.

    2 h

Where it leads

Part of these career paths