Security Operations · Intermediate
Detection Engineering
Turn what an investigation learns into tested, version-controlled detections: write Sigma rules, test them positively and negatively, tune false positives, and run them on a lab-local Wazuh manager.
About this course
A SOC analyst who has worked an incident knows what *should* have been caught. Detection engineering is the discipline of turning that knowledge into detection content a team can maintain, measure and retire — not a rule typed into a console and forgotten, but code with tests, review, coverage and a change history. You work on `soc01`, an Ubuntu 24.04 machine that carries the SOC analyst toolkit (auditd, fail2ban, nginx and the ULC-006 synthetic generator) plus a single-node **Wazuh manager**, the **Sigma** detection-as-code toolchain (`sigma-cli`, pySigma and a SQLite backend), and an offline copy of the MITRE ATT&CK and D3FEND data. Everything you investigate is **synthetic**, generated on your own machine from documentation-range addresses; no production log, no customer data and no live target is ever involved. Across ten lessons you learn the detection lifecycle; how to normalise three disagreeing log families into one queryable event stream; how to write a Sigma rule whose logsource, detection, condition, level, tags and false positives pass `sigma check`; how to convert rules to queries with a processing pipeline and see exactly what your backend does and does not support; how to test a rule so it fires on the behaviour and stays silent on a clean day; how to measure and tune false positives with a written rationale; how to keep rules as code with stable ids, an ATT&CK coverage matrix, a peer-review checklist and a fail-closed CI gate; and how to run the same detections continuously on a host and on a Wazuh manager, promoting a rule through a change record with a rollback. The final project hands you an unseen incident bundle and asks for a complete detection pack — rules, pipeline, tests, a false-positive report, a coverage matrix, a passing CI gate and a rollout note — graded against a rubric and automated lab checks that run your rules against held-back synthetic samples.
- Content time
- 17 h 45 min
- Lessons
- 10
- Certificate
- Yes
- on completion
Lesson 1 is free. Enroll in a career path to access its full courses.
Lesson 1 is a free preview — read it without an account.

Outline
Lessons
Lesson 1: From analyst to detection engineerFree preview
What detection engineering is, the lifecycle every detection moves through, and the telemetry you will build detections from.
1 h 15 minLesson 2: Normalising telemetry into one event stream
Turn three log families that disagree on time and field names into one UTC SQLite table a rule can query once and run everywhere.
1 h 50 minLesson 3: Anatomy of a Sigma rule
Write a portable, vendor-neutral detection in Sigma — title, logsource, detection, condition, level, tags and false positives — and check it against the specification.
1 h 50 minLesson 4: Pipelines and conversion — from rule to query
Write a pySigma pipeline that maps portable rules onto your schema, convert rules to SQL, and learn exactly what the SQLite backend supports and what it does not.
2 hLesson 5: Positive and negative fixtures
A rule is only real when it fires where it should and nowhere else. Write positive and negative fixtures and run every rule like CI, across seeds.
1 h 50 minLesson 6: Measuring and tuning false positives
Add a benign administrator-noise day, measure each rule's false positives against it, and tune by filter with a written rationale — never by silently raising a threshold.
1 h 40 minLesson 7: The rule repository
Keep detections as code — a repository layout, stable ids and status, a peer-review checklist, and an ATT&CK coverage matrix generated from the rules themselves.
1 h 40 minLesson 8: CI for detections
Build a fail-closed CI gate that runs syntax, policy, tests and coverage on every change, install it as a pre-push hook, and prove it blocks a rule with no negative fixture.
1 h 40 minLesson 9: Continuous detection on a running platform
Deploy a detection to a lab-local Wazuh manager through a scoped change, test it with wazuh-logtest, and run a self-test on a timer so a broken rule set is caught automatically.
2 hLesson 10: Wazuh rules, decoders and the detection lifecycle
Translate a second detection to Wazuh, understand decoders and the ATT&CK version gap between tools, and promote a rule through a change record with a rollback and a retirement plan.
2 h
Where it leads