Detection Engineering roadmap

Build, test, and tune detections as code: Sigma rules, ATT&CK coverage, and false-positive management. Move from SOC and log analysis into writing, testing, and version-controlling high-fidelity detections.

1 courses6 resourcesSOC analyst

Step-by-step path

  1. Logs, telemetry, and the detection lifecycle
  2. Write Sigma rules and map coverage to MITRE ATT&CK
  3. Test detections with Atomic Red Team and manage rules as code
  4. Build a portfolio artifact and publish a short writeup.