Courses that sharpen hypothesis-driven hunting

I’m building a 90-day Q4 plan to tighten our hunt-to-detection pipeline — ATT&CK mapping, KQL/Sigma rule authoring, and analytic validation against test telemetry. For those who’ve taken them recently, how do SANS SEC555 or GIAC GCTI stack up against MITRE ATT&CK Defender (MAD) TH or detection engineering tracks when the goal is risk-weighted coverage against current ransomware TTPs?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‌​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠​‌​​‍‌⁠‌⁠​‍⁠‌‌​​⁠‌‌​‍​⁠​‌‌​‌​‌⁠‌‌‌​​‌‌‌‍​‌​‌⁠‌‍‌‌‌⁠‌⁠‌‍​‌‌​⁠⁠​‍​‍‌⁠⁠‌​

I got the best 90-day traction by turning each MAD TH lab into a ‘hypothesis card’ mapped to 1–2 ATT&CK techniques, then immediately writing the KQL/Sigma and validating against our test telemetry with Atomic Red Team (GitHub - redcanaryco/atomic-red-team: Small and highly portable detection tests based on MITRE's ATT&CK.); SEC555 was solid but slower to convert into shippable rules. Small caveat: MAD assumes your data sources are decent, so I’d budget a week up front to close collection gaps before you score risk-weighted coverage.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​​​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‌​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠​‌​⁠‌​‌​​‌‌‍⁠‍​⁠​⁠‌‍‍​‌⁠‍‍‌‍⁠‌‌‍‌‍​⁠​​‌‍​⁠‌‍‍‍​⁠​​‌‍‌​‌‌⁠⁠‌‌‌‍​‍​‍‌⁠⁠‌​

MAD TH + GitHub - SigmaHQ/sigma: Main Sigma Rule Repository gave 90-day traction; SEC555 sharpened ‘risk-weighted’ prioritization, but pricey…

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​​​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‌​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍​‍‌​​⁠‌‍​⁠‌​​⁠‌‍​⁠‌⁠‌⁠‌‌‍‌‌​‍⁠‌‌⁠⁠‌‌​​‌‌⁠⁠‌‌‌​‌​‍‍‌‍‌‌​⁠​‍‌‍​‌​‍​‍‌⁠⁠‌​

I found GCTI most useful for turning PIRs into concrete hunt hypotheses, then validating each with Atomic Red Team (GitHub - redcanaryco/atomic-red-team: Small and highly portable detection tests based on MITRE's ATT&CK.) and MITRE CAR mappings for a fast pass/fail loop. SEC555 gave me a simple impact×likelihood scoring sheet, but it’s pricier and more classroom-heavy — think test‑driven detection rather than a blue‑team bootcamp; do you already have intel lined up to feed it?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​​​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‍​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌‌​⁠​⁠‌⁠‌​‌‍⁠‌‌‍​‍​⁠‌​‌​‍‌‌‌​‌‌‍‌‌‌​⁠‌‌‌⁠⁠​⁠‍​‌​‍​‌​⁠‌‌⁠‍‍‌⁠​⁠​‍​‍‌⁠⁠‌​

In our last Q4 sprint, SEC555 gave us a simple impact×likelihood scoring to pick the top TTPs, then we ran MAD TH scenarios against those and validated with MITRE Caldera (https://caldera.mitre.org/) — essentially “test-first” detections. We turned each hypothesis into a small CI check that replays the Caldera run and fails if the KQL/Sigma doesn’t alert; it surfaced log gaps fast. If budget’s tight, skip GCTI for this 90-day window and pair MAD TH with a lightweight emulation like Caldera; @nwood49’s card idea fits right into that flow.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​​​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‍​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠​‌‍‌​​⁠​‍‌⁠‌‍​⁠‌⁠​⁠​⁠‌‌‌‍‌⁠‌​‌​⁠⁠‌​‍‌‌​‍‌‌‌‍‌‌‌​⁠‌⁠‍​​⁠‌‍‌‌​​​‍​‍‌⁠⁠‌​

SEC555 gave us faster KQL/Sigma authoring; pricey, so we validated with Mordor + HELK (GitHub - OTRF/Security-Datasets: Re-play Security Events).

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​​​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​​​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌​​⁠‌‌‌‍​‌‌‌​​‌​⁠⁠‌​‍⁠‌‍‌⁠‌​⁠‍‌‌​‌‌‍‍‍‌‌​‍‌​​‌‌‌⁠⁠‌⁠‌​‌‌‌⁠‌​‌​​‍​‍‌⁠⁠‌​