To access material, start machines and answer questions login.
This room aims to serve as a supplementary space for Sigma rule creation. In this scenario, you will act as one of the Detection Engineers who will craft Sigma Rules based on attack details collected by an Incident Response team.
Prerequisites
This room requires basic knowledge of detection engineering and Sigma rule creation. We recommend going through the following rooms before attempting this challenge.
Sigma Validator Interface
In this room, you will be using the Sigma Validator, which is a TryHackMe tool for validating your Sigma rules! Note that this is an internal tool exclusively created for TryHackMe scenarios and is not accessible via the internet.
Before we proceed, deploy the attached machine for this task, as it may take 1-2 minutes to initialize the services. Then, use the following link to access the interface:
Set up your virtual environment
How to use the Sigma Validator Interface:
- Rules: Select which Sigma rule you will work on.
- Attack Log: Use the attack log preview to understand the fields and values associated with the malicious event.
- Fields you can use: Shows the fields you can use to write that specific detection.
- Detection: Write your Sigma rule detection logic in this section.
- Validate Detection: Submit your Sigma rule and see if it detects the attack.
Ready to learn Cyber Security?
The SigHunt room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in
