Curriculum
-
1
Free Preview
-
2
Chapter 1: Understanding Sigma and Its Importance
-
(Included in full purchase)
Understanding Sigma and Its Importance
-
(Included in full purchase)
-
3
Chapter 2: Anatomy of a Sigma Rule
-
(Included in full purchase)
Anatomy of a Sigma Rule
-
(Included in full purchase)
-
4
Chapter 3: Sigma Rule Logic and Conditions
-
(Included in full purchase)
Sigma Rule Logic and Conditions
-
(Included in full purchase)
-
5
Chapter 4: Creating Rules for Windows Logs
-
(Included in full purchase)
Creating Rules for Windows Logs
-
(Included in full purchase)
-
6
Chapter 5: Creating Rules for Linux and Network Logs
-
(Included in full purchase)
Creating Rules for Linux and Network Logs
-
(Included in full purchase)
-
7
Chapter 6: ATT&CK Mapping and TTP-Based Detection
-
(Included in full purchase)
ATT&CK Mapping and TTP-Based Detection
-
(Included in full purchase)
-
8
Chapter 7: Threat Simulation and Rule Testing
-
(Included in full purchase)
Threat Simulation and Rule Testing
-
(Included in full purchase)
-
9
Chapter 8: Sigma Rule Anti-Patterns and Best Practices
-
(Included in full purchase)
Sigma Rule Anti-Patterns and Best Practices
-
(Included in full purchase)
-
10
Chapter 9: Real-World Detection Use Cases
-
(Included in full purchase)
Real-World Detection Use Cases
-
(Included in full purchase)
-
11
Chapter 10: Sigma Rules in SOC Workflows
-
(Included in full purchase)
Sigma Rules in SOC Workflows
-
(Included in full purchase)
-
12
Chapter 11: Converting Sigma to SIEM Queries
-
(Included in full purchase)
Converting Sigma to SIEM Queries
-
(Included in full purchase)
-
13
Chapter 12: Backend Limitations and Field Mapping Challenges
-
(Included in full purchase)
Backend Limitations and Field Mapping Challenges
-
(Included in full purchase)
-
14
Chapter 13: Automating Detection Delivery with CI/CD
-
(Included in full purchase)
Automating Detection Delivery with CI/CD
-
(Included in full purchase)
-
15
Chapter 14: Managing Rule Packs and Rule Versioning
-
(Included in full purchase)
Managing Rule Packs and Rule Versioning
-
(Included in full purchase)
-
16
Chapter 15: Threat Hunting with Sigma
-
(Included in full purchase)
Threat Hunting with Sigma
-
(Included in full purchase)
-
17
Chapter 16: Intelligence-Driven Detection Engineering
-
(Included in full purchase)
Intelligence-Driven Detection Engineering
-
(Included in full purchase)
-
18
Chapter 17: Sigma in Open Source XDR
-
(Included in full purchase)
Sigma in Open Source XDR
-
(Included in full purchase)
-
19
Chapter 18: The Future of Sigma and Detection-as-Code
-
(Included in full purchase)
The Future of Sigma and Detection-as-Code
-
(Included in full purchase)
-
20
Appendices
-
(Included in full purchase)
Appendices
-
(Included in full purchase)
-
21
Index
-
(Included in full purchase)
Index
-
(Included in full purchase)
About the Course
Practical Detection Engineering with Sigma is a hands-on guide to building, testing, and operationalizing modern detections in real SOC environments. The book walks you step by step through the full detection engineering lifecycle—from understanding Sigma fundamentals to writing structured rules and deploying them across SIEM and XDR platforms. You will learn how to translate adversary behavior into behavior-based detections, aligned with MITRE ATT&CK, create rules for Windows, Linux, and network telemetry, and convert them into backend-specific queries for platforms such as Elastic, Splunk, Microsoft Sentinel, and Wazuh. Practical examples demonstrate how to validate detections using real and simulated attack data, reduce false positives, and design alerts that analysts can confidently triage. From rule creation to CI/CD automation, version control, and large-scale rule management, this book equips you to build scalable, maintainable, and production-ready detection programs aligned with modern security operations.
About the Author
Wojciech Ciemski is a cybersecurity engineer and detection specialist with over a decade of hands-on experience. His work focuses on detection engineering, Sigma Rule Language, and research-driven analysis of adversary behavior mapped to MITRE ATT&CK. He designs and tests scalable SIEM and XDR detection pipelines, based on real-world threat data.