Sigma Rule Writing

Write a detection once. Run it on every SIEM.

A detection tied to one SIEM's query language dies when you change platforms, and the same logic has to be rewritten by hand for every backend you run. Sigma is the vendor-neutral format that fixes this: you write a rule once in a small YAML language, and convert it to Splunk, Microsoft, or Elastic without rewriting it. This course teaches the full craft, from rule anatomy and detection logic through writing rules that survive production, converting them across backends, and correlating across events, to validating and shipping a maintained detection library.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 10 CPE Credits

What you'll be able to do

✓Read a threat for the behavior worth detecting and write it as a Sigma rule with correct anatomy, logsource, detection logic, and ATT&CK tags
✓Compose detection logic with selections, filters, modifiers, and the condition, controlling precedence so a rule matches exactly what you intend
✓Write rules that survive production: durable against evasion, tuned against noise, with an honest false-positive profile and the right level and status
✓Convert one rule to Splunk, Microsoft, and Elastic with sigma-cli, and read each output to confirm the fields, event source, and logic survived
✓Detect multi-event patterns no single rule can see with the four correlation types, from brute force and password spray to kill-chain sequences
✓Validate a rule against data before it ships, and manage a maintained, version-controlled rule library through its lifecycle
SEC408 | Advanced tier | 5 modules across 4 phases | 8–10 hours at your own pace | 10 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Course Orientation

Module 0Course OrientationCourse Preview

What Sigma Rule Writing teaches: write a detection once in Sigma's vendor-neutral YAML and deploy it to any SIEM. The rule anatomy, the detection-logic language, the craft of writing rules that survive production, conversion across Splunk, Sentinel, and Elastic, and the correlation and validation that make a detection pack you keep. The discipline, the toolchain, and how the course is built. Start here.

Phase 1: Writing Rules

Module 1The Sigma Model

What a Sigma rule is as an object you author. The full YAML anatomy, the logsource abstraction of category, product, and service that makes a rule portable, the detection block in outline, the metadata that gives a rule identity and a lifecycle, ATT&CK tagging, and reading SigmaHQ rules as a peer rather than a black box.

Show 8 lessonsHide lessons
  1. 1.11.1 The Anatomy of a Sigma Rule
  2. 1.21.2 Logsource: Category, Product, and Service
  3. 1.31.3 The Detection Block in Outline
  4. 1.41.4 Metadata That Matters: id, status, level, and related
  5. 1.51.5 Tags and ATT&CK Mapping
  6. 1.61.6 Reading SigmaHQ Rules as a Peer
  7. 1.7Module Summary
  8. 1.8Check My Knowledge
Module 2Detection Logic

The detection block in depth. How a selection matches, the full set of field modifiers from contains and startswith through regex, CIDR, base64, and windash, the condition language with its quantifiers and operator precedence, and the exclusion logic that carves known-good activity out of a match. The language you write detections in, taught precisely.

Show 8 lessonsHide lessons
  1. 2.12.1 How a Selection Matches
  2. 2.22.2 String Modifiers
  3. 2.32.3 Transform and Type Modifiers
  4. 2.42.4 Encoding and Evasion Modifiers
  5. 2.52.5 The Condition Language and Precedence
  6. 2.62.6 Filters, Exclusions, and Composing a Rule
  7. 2.7Module Summary
  8. 2.8Check My Knowledge

Phase 2: Production Quality

Module 3Writing Rules That Survive Production

The gap between a rule that is correct and a rule that survives production. Why good rules get switched off, detecting on durable fields instead of fragile indicators, the specificity dial between too broad and too narrow, documenting false positives and tuning, the SigmaHQ quality conventions, and taking a noisy rule to production-ready.

Show 8 lessonsHide lessons
  1. 3.13.1 Why Good Rules Get Switched Off
  2. 3.23.2 Durable Detections: Stable vs Volatile Fields
  3. 3.33.3 The Specificity Dial
  4. 3.43.4 False Positives and the Tuning Loop
  5. 3.53.5 Rule Quality and Review
  6. 3.63.6 From Noisy to Production-Ready
  7. 3.7Module Summary
  8. 3.8Check My Knowledge

Phase 3: Conversion

Module 4Conversion Across Backends

How one Sigma rule becomes a query on any SIEM. The conversion pipeline, the two-part system of target and pipeline, how fields and logsources are mapped to each platform, what converts cleanly and what degrades or breaks, reading and verifying the converted query, and taking a single rule across Splunk, Microsoft, and Elasticsearch.

Show 8 lessonsHide lessons
  1. 4.14.1 What Conversion Actually Does
  2. 4.24.2 Targets and Pipelines: The Two-Part System
  3. 4.34.3 Field and Logsource Mapping
  4. 4.44.4 What Converts Cleanly and What Breaks
  5. 4.54.5 Reading and Verifying Converted Output
  6. 4.64.6 One Rule Across Three Backends
  7. 4.7Module Summary
  8. 4.8Check My Knowledge

Phase 4: Validate and Ship

Module 5Validate, Correlate, Ship

Turning rules into an operational detection practice. Validating a rule against real data before it ships, the correlation model for detecting across multiple events, the counting and sequence correlation types, shipping detections as code through a lifecycle, and a course capstone that assembles everything from a threat to a deployed detection.

Show 8 lessonsHide lessons
  1. 5.15.1 Validating a Rule Against Data
  2. 5.25.2 Beyond One Event: The Correlation Model
  3. 5.35.3 Counting Correlations
  4. 5.45.4 Sequence Correlations
  5. 5.55.5 Shipping: The Rule Lifecycle and Detection as Code
  6. 5.65.6 Course Capstone
  7. 5.7Module Summary
  8. 5.8Check My Knowledge

Phase 0: Course Resources

ResourcesCheatsheets

The rule anatomy, the modifiers, what survives conversion, and the correlation types with their limits.

Show 4 lessonsHide lessons
  1. 1The Rule, and the Fields That Decide Its Fate
  2. 2Detection Logic and the Modifiers
  3. 3Conversion, and What Does Not Survive It
  4. 4Validating, Correlating and Shipping
ResourcesCookbooks

Ordered procedures for writing a rule from a report, adopting a community rule, taking a noisy rule to production, and building a repository.

Show 4 lessonsHide lessons
  1. 1Writing a Rule From a Threat Report
  2. 2Adopting a Community Rule
  3. 3Taking a Noisy Rule to Production
  4. 4Standing Up a Rule Repository
ResourcesWalkthroughs

Four cases reasoned end to end, including the rule that converted perfectly and matched nothing.

Show 4 lessonsHide lessons
  1. 1The Rule That Converted Perfectly
  2. 2The Rule That Was Broader Than Anybody Read
  3. 3The Rule Nobody Should Have Tightened
  4. 4The Correlation That Never Correlated
ResourcesPlayground

sigma-cli, the public rule repository, and log data of your own to validate against.

ResourcesOperational Reference

The full rule anatomy, every modifier, the condition and correlation syntax, the sigma-cli conversion and validation commands, and the rule-quality conventions from the course in one place, organized by task. The working kit you carry out of the course to the rules you write.

Show 1 lessonHide lessons
  1. 1Operational Reference
ResourcesReferences & Further Reading

The Sigma specification and documentation, the pySigma toolchain and backends, ATT&CK, Atomic Red Team, and the backend platform documentation used throughout the Sigma Rules course, organized by category.

Course Completion

CompletionCourse Exam

Sigma Rule Writing end-of-course exam: one rule, two backends, clean conversion on both, and only one that ever fires. Testing whether you can tell a syntax success from a semantic failure and measure how far it reaches.

Show 1 lessonHide lessons
  1. 1Course Completion. Sigma Rule Writing

Course overview

Sigma Rule Writing teaches you to write detection rules that are portable across SIEMs and good enough to run in production. You start from the rule model and detection-logic language, learn to write rules that survive a noisy real environment, convert them to any backend, extend them with correlation for the attacks a single event cannot show, and validate and ship them as a maintained library. Learn how to:

✓ Write Sigma rules with correct anatomy, logsources, detection logic, modifiers, and ATT&CK tags
✓ Make rules survive production: durable against evasion, tuned against noise, with an honest false-positive profile
✓ Convert one rule to Splunk, Microsoft, and Elastic with sigma-cli, and verify each output
✓ Detect multi-event patterns with correlation: brute force, password spray, and kill-chain sequences
✓ Validate a rule against data before it ships and manage it through a version-controlled lifecycle

By the end you can take a threat from a report to a deployed, validated detection that runs on whichever SIEMs your organization uses.

How this course works

A Sigma rule is a claim that a behavior is visible in a log source. This course runs the same loop for every rule it writes, because the difference between a rule that works and a rule that exists is the last three steps.

1. Name the behavior, not the tool. A rule matching an executable name breaks when the attacker renames it. A rule matching what the technique has to do survives.

2. Write against a log source you actually have. The most elegant rule in the world is inert if your estate never collects the field it matches on. Establish the source before the logic.

3. Render it to the backend you run. Sigma is a portable format, and portability is only useful if you check what the converter produced. The same rule becomes different queries in different backends.

4. Test both directions. Fire the behavior and confirm the rule matches. Then run it against a week of normal activity and count what it returned. A rule tested only positively is half tested.

5. Ship it with its false positive documented. Every rule has one. Writing it down is what stops the next analyst deleting the rule instead of tuning it.

What this course assumes

No minimum experience and no prerequisite course. YAML, log sources, field mappings and the backend model are all explained where they first appear.

What makes it go faster: any prior exposure to a SIEM query language, and a log source of your own to test against. Neither is required, and the course provides sample data for every rule it writes.

What this course does not cover: operating a SIEM, incident response, and the detection engineering program around the rules. This is the rule-writing craft, taught deeply, and the program that consumes those rules is a separate course.

Who this course is for

You are a detection engineer, SOC analyst, or threat hunter who consumes Sigma rules from the community repository but wants to author your own, debug a conversion that fails, and write rules good enough to run in production. Anyone building a portable detection capability across more than one SIEM belongs here. The course is self-contained, every concept explained at first use, so an experienced reader can move fast and a newer one is never left behind. It is for you if you want to:

✓ Author your own Sigma rules instead of only consuming rules others wrote
✓ Write detections once and run them on whichever SIEM your organization uses
✓ Understand why a conversion produces an empty query, and fix the field or pipeline behind it
✓ Detect threshold, spray, and sequence attacks that no single-event rule can catch

What you'll learn

By the end of Sigma Rule Writing you will be able to:

✓ Read a threat for the behavior worth detecting and express it as a Sigma rule
✓ Compose detection logic with selections, filters, and modifiers, controlling precedence so a rule matches exactly what you intend
✓ Choose durable detection traits over brittle ones so a rule catches variants and survives an attacker's changes
✓ Tune a rule against real noise and document its false-positive profile, level, and status
✓ Convert a rule to KQL, SPL, and Elastic with sigma-cli, and read each output to confirm the fields, event source, and logic survived
✓ Write correlation rules across the four types: event_count, value_count, temporal, and temporal_ordered
✓ Validate a rule with a two-sided test against data and keep it working through edits with regression tests
✓ Manage a version-controlled rule library and ship detections through their lifecycle

Key course takeaways

✓ The craft to write a Sigma rule that is correct, durable, tuned, and portable across every major SIEM
✓ A working method for conversion: the pipeline that maps fields, what converts cleanly, what degrades, and how to verify
✓ The correlation model for detecting attacks that live in the relationship between events, not any single one
✓ The validation and lifecycle discipline that turns rule writing into a repeatable engineering practice

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

✓ Walkthroughs take a rule and show what happened to it: the rule that converted perfectly, the rule that was broader than anybody read, the rule nobody should have tightened, and the correlation that never correlated.
✓ A cookbook for the four jobs: writing a rule from a threat report, adopting a community rule, taking a noisy rule to production, and standing up a repository.
✓ A command cheatsheet on the fields that decide a rule's fate, the modifiers, what does not survive conversion, and shipping.
✓ An operational reference consolidating the syntax and the backend behavior, for the point at which you are writing rather than learning.
✓ A playground where two of the three things you need install in a minute: the toolchain, the public SigmaHQ rules to read, and the log data that decides whether your rules actually work.
✓ A references module for the specification and the backend documentation.

Things you need to know

What are the prerequisites for this course?

Basic YAML familiarity (if you have edited a config file, you have enough) and comfort reading at least one SIEM query language such as KQL or SPL. No prior Sigma experience is required. Every concept is taught at first use, and an experienced reader can skip past what they already know.

Do I need a SIEM to take this course?

No. You can write, convert, and reason about rules without a live SIEM. Where the course shows converted queries for Splunk, Microsoft, and Elastic, you can follow whichever backend you have access to, and the conversion and validation concepts apply the same way regardless of platform.

How does this relate to SEC401 (Threat Detection Engineering) and SEC407 (Detection as Code)?

This course teaches the craft of writing portable detection rules in Sigma. SEC401 teaches detection methodology and authoring in Microsoft Sentinel and KQL. SEC407 teaches the pipeline that operates a detection library at scale: CI, version control, and automated deployment. Each stands alone; together they cover authoring, portability, and operations. Neither is a prerequisite for this course.

How will the course benefit your career?

Sigma is the community standard for shareable detection rules, and the cybersecurity professionals who can author and debug them, rather than only consume them, are in demand. Because the skill is vendor-neutral, it travels with you regardless of which SIEM an employer runs, and it feeds directly into detection-as-code roles where portable rules are the input a pipeline depends on.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.