Applied Network Defense Courses
(2 courses)Explore all courses, labs, and learning resources from Applied Network Defense.
Applied Network Defense – Investigation Theory
Investigation Theory is a comprehensive cybersecurity course designed for security analysts, incident responders, threat hunters, and digital forensics professionals who want to master the investigative process behind effective security operations. Rather than focusing on a specific SIEM, EDR, or forensic platform, this course teaches the mental models, analytical frameworks, and decision-making techniques used by experienced investigators to uncover, understand, and respond to security incidents.
Applied Network Defense | Detection Engineering with Sigma
Detection Engineering with Sigma will teach you how to write and tune Sigma rules to find evil in logs using real-world examples that take you through the detection engineering process. We’ll dissect real Sigma detection rules focused on finding a variety of malicious activity in diverse log sources. Once you have a good handle on these components, you’ll start writing and tuning your own rules in a series of case studies. In some case studies, I’ll describe a detection gap and you’ll write a rule on your own before I show you how I tackled the problem myself. In other scenarios, you’ll write or modify a rule on your own and submit it to me for feedback. In this course, you are never alone! I will be with you 100% of the way to help you understand the structure of Sigma rules, how to get from idea to finished rule, and best practices for writing resilient rules.

