Sigma Rule Writing
Write a detection once. Run it on every SIEM.
A detection tied to one SIEM's query language dies when you change platforms, and the same logic has to be rewritten by hand for every backend you run. Sigma is the vendor-neutral format that fixes this: you write a rule once in a small YAML language, and convert it to Splunk, Microsoft, or Elastic without rewriting it. This course teaches the full craft, from rule anatomy and detection logic through writing rules that survive production, converting them across backends, and correlating across events, to validating and shipping a maintained detection library.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Course Orientation
What Sigma Rule Writing teaches: write a detection once in Sigma's vendor-neutral YAML and deploy it to any SIEM. The rule anatomy, the detection-logic language, the craft of writing rules that survive production, conversion across Splunk, Sentinel, and Elastic, and the correlation and validation that make a detection pack you keep. The discipline, the toolchain, and how the course is built. Start here.
Phase 1: Writing Rules
What a Sigma rule is as an object you author. The full YAML anatomy, the logsource abstraction of category, product, and service that makes a rule portable, the detection block in outline, the metadata that gives a rule identity and a lifecycle, ATT&CK tagging, and reading SigmaHQ rules as a peer rather than a black box.
Show 8 lessonsHide lessons
The detection block in depth. How a selection matches, the full set of field modifiers from contains and startswith through regex, CIDR, base64, and windash, the condition language with its quantifiers and operator precedence, and the exclusion logic that carves known-good activity out of a match. The language you write detections in, taught precisely.
Phase 2: Production Quality
The gap between a rule that is correct and a rule that survives production. Why good rules get switched off, detecting on durable fields instead of fragile indicators, the specificity dial between too broad and too narrow, documenting false positives and tuning, the SigmaHQ quality conventions, and taking a noisy rule to production-ready.
Phase 3: Conversion
How one Sigma rule becomes a query on any SIEM. The conversion pipeline, the two-part system of target and pipeline, how fields and logsources are mapped to each platform, what converts cleanly and what degrades or breaks, reading and verifying the converted query, and taking a single rule across Splunk, Microsoft, and Elasticsearch.
Show 8 lessonsHide lessons
Phase 4: Validate and Ship
Turning rules into an operational detection practice. Validating a rule against real data before it ships, the correlation model for detecting across multiple events, the counting and sequence correlation types, shipping detections as code through a lifecycle, and a course capstone that assembles everything from a threat to a deployed detection.
Phase 0: Course Resources
The rule anatomy, the modifiers, what survives conversion, and the correlation types with their limits.
Ordered procedures for writing a rule from a report, adopting a community rule, taking a noisy rule to production, and building a repository.
Four cases reasoned end to end, including the rule that converted perfectly and matched nothing.
sigma-cli, the public rule repository, and log data of your own to validate against.
The full rule anatomy, every modifier, the condition and correlation syntax, the sigma-cli conversion and validation commands, and the rule-quality conventions from the course in one place, organized by task. The working kit you carry out of the course to the rules you write.
Show 1 lessonHide lessons
The Sigma specification and documentation, the pySigma toolchain and backends, ATT&CK, Atomic Red Team, and the backend platform documentation used throughout the Sigma Rules course, organized by category.
Course Completion
Sigma Rule Writing end-of-course exam: one rule, two backends, clean conversion on both, and only one that ever fires. Testing whether you can tell a syntax success from a semantic failure and measure how far it reaches.
Show 1 lessonHide lessons
Course overview
Sigma Rule Writing teaches you to write detection rules that are portable across SIEMs and good enough to run in production. You start from the rule model and detection-logic language, learn to write rules that survive a noisy real environment, convert them to any backend, extend them with correlation for the attacks a single event cannot show, and validate and ship them as a maintained library. Learn how to:
By the end you can take a threat from a report to a deployed, validated detection that runs on whichever SIEMs your organization uses.
How this course works
A Sigma rule is a claim that a behavior is visible in a log source. This course runs the same loop for every rule it writes, because the difference between a rule that works and a rule that exists is the last three steps.
1. Name the behavior, not the tool. A rule matching an executable name breaks when the attacker renames it. A rule matching what the technique has to do survives.
2. Write against a log source you actually have. The most elegant rule in the world is inert if your estate never collects the field it matches on. Establish the source before the logic.
3. Render it to the backend you run. Sigma is a portable format, and portability is only useful if you check what the converter produced. The same rule becomes different queries in different backends.
4. Test both directions. Fire the behavior and confirm the rule matches. Then run it against a week of normal activity and count what it returned. A rule tested only positively is half tested.
5. Ship it with its false positive documented. Every rule has one. Writing it down is what stops the next analyst deleting the rule instead of tuning it.
What this course assumes
No minimum experience and no prerequisite course. YAML, log sources, field mappings and the backend model are all explained where they first appear.
What makes it go faster: any prior exposure to a SIEM query language, and a log source of your own to test against. Neither is required, and the course provides sample data for every rule it writes.
What this course does not cover: operating a SIEM, incident response, and the detection engineering program around the rules. This is the rule-writing craft, taught deeply, and the program that consumes those rules is a separate course.
Who this course is for
You are a detection engineer, SOC analyst, or threat hunter who consumes Sigma rules from the community repository but wants to author your own, debug a conversion that fails, and write rules good enough to run in production. Anyone building a portable detection capability across more than one SIEM belongs here. The course is self-contained, every concept explained at first use, so an experienced reader can move fast and a newer one is never left behind. It is for you if you want to:
What you'll learn
By the end of Sigma Rule Writing you will be able to:
Key course takeaways
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Things you need to know
What are the prerequisites for this course?
Basic YAML familiarity (if you have edited a config file, you have enough) and comfort reading at least one SIEM query language such as KQL or SPL. No prior Sigma experience is required. Every concept is taught at first use, and an experienced reader can skip past what they already know.
Do I need a SIEM to take this course?
No. You can write, convert, and reason about rules without a live SIEM. Where the course shows converted queries for Splunk, Microsoft, and Elastic, you can follow whichever backend you have access to, and the conversion and validation concepts apply the same way regardless of platform.
How does this relate to SEC401 (Threat Detection Engineering) and SEC407 (Detection as Code)?
This course teaches the craft of writing portable detection rules in Sigma. SEC401 teaches detection methodology and authoring in Microsoft Sentinel and KQL. SEC407 teaches the pipeline that operates a detection library at scale: CI, version control, and automated deployment. Each stands alone; together they cover authoring, portability, and operations. Neither is a prerequisite for this course.
How will the course benefit your career?
Sigma is the community standard for shareable detection rules, and the cybersecurity professionals who can author and debug them, rather than only consume them, are in demand. Because the skill is vendor-neutral, it travels with you regardless of which SIEM an employer runs, and it feeds directly into detection-as-code roles where portable rules are the input a pipeline depends on.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.