CB
CyberBlueAcademy
CoursesSyllabusToolsPricing
CoursesCyberBlueSOC AcademyModule 12

Module 12: Sigma — Detection Engineering

Write universal detection rules. Make your SIEM smarter.

Tools:SigmaWazuh
6
Lessons
6
Hands-on Labs

Lessons

1

Why Detection Engineering Matters

From reacting to creating alerts

2

Sigma Rule Structure

Title, logsource, detection, tags

3

Writing Your First Detection

Brute force, suspicious process

4

Sigma → Wazuh/OpenSearch

Converting and deploying rules

5

Tuning & False Positives

Filters, exclusions, real-world rules

6

SigmaHQ: 3,000+ Rules

Navigating the repository

Labs

Lab 12.1 — Read a Sigma Rule

5 rules. Explain and map ATT&CK.

Intermediate

Lab 12.2 — Brute Force Detection

Write 5+ failed logons in 5m rule.

Intermediate

Lab 12.3 — Suspicious PowerShell

Detect encoded PowerShell.

Advanced

Lab 12.4 — Threat Report → Detection

Write, convert, deploy, test.

Advanced

Lab 12.5 — Tune a Noisy Rule

200/day → <5/day without misses.

Advanced

Lab 12.6 — SigmaHQ Deployment

10 rules. Batch-convert. Deploy.

Expert
CB
CyberBlueAcademy

The SANS alternative you can actually afford. Real tools. Real labs. Real skills.

Course

  • Syllabus
  • Tools
  • Certification
  • Pricing

Platform

  • CyberBlueSOC (GitHub)
  • Installation Guide
  • Documentation

Community

  • Discord
  • Twitter / X
  • LinkedIn

© 2026 CyberBlue Academy. All rights reserved.

Privacy PolicyTerms of Service