Skip to main content
Room Banner
Room Icon

SigHunt

Max room.

You are tasked to create detection rules based on a new threat intel.

medium

60 min

10,481

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

This room aims to serve as a supplementary space for Sigma rule creation. In this scenario, you will act as one of the Detection Engineers who will craft Sigma Rules based on attack details collected by an Incident Response team.

Prerequisites

This room requires basic knowledge of detection engineering and Sigma rule creation. We recommend going through the following rooms before attempting this challenge.

Sigma Validator Interface

In this room, you will be using the Sigma Validator, which is a TryHackMe tool for validating your Sigma rules! Note that this is an internal tool exclusively created for TryHackMe scenarios and is not accessible via the internet.

Before we proceed, deploy the attached machine for this task, as it may take 1-2 minutes to initialize the services. Then, use the following link to access the interface: 

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off

How to use the Sigma Validator Interface:

  • Rules: Select which Sigma rule you will work on.
  • Attack Log: Use the attack log preview to understand the fields and values associated with the malicious event.
  • Fields you can use: Shows the fields you can use to write that specific detection.
  • Detection: Write your Sigma rule detection logic in this section.
  • Validate Detection: Submit your Sigma rule and see if it detects the attack.

Sigma Validator interface.

Answer the questions below
Let's start creating Sigma rules!