VietCyberCareers Find Your Path
Project

Create Sigma Rules

Write detection rules and test them against log data.

Sigma is an open, SIEM-agnostic format for writing detection rules in plain YAML. Pick one behavior from your Atomic Red Team run and write a Sigma rule that would flag it, then test the rule against your own logs.

Blue Team
Estimated time: 2-3 hours

Related career paths