I’m after training that focuses on identifying and mitigating current malware tradecraft rather than just collecting IOCs — think BYOVD, DLL sideloading, and indirect syscalls seen in Q4 2025. Has anyone taken a course that blends reversing (Ghidra/IDA) with building durable detections (Sigma/YARA) and validating them via purple-team exercises against ATT&CK techniques? Bonus if labs include EDR telemetry on Windows 11 and Server 2022 so we can tune detections, not just admire samples.
SpecterOps’ “Adversary Tactics: Detection Engineering” hits reversing + Sigma/YARA with purple drills: https://specterops.io/training/adversary-tactics-detection-engineering. Want remote or onsite?
Co-sign @chase1984, but if you want deeper reversing blended with detections, SANS FOR610 + SEC599 was the best combo I’ve taken: we tore apart DLL sideloading in Ghidra/IDA, turned it into YARA/Sigma, then validated via ATT&CK runs with Atomic Red Team. , it’s pricey and two full weeks, but it held up against BYOVD and indirect syscalls we saw in late 2025. If budget’s tight, replicate the purple drills in a home lab with GitHub - redcanaryco/atomic-red-team: Small and highly portable detection tests based on MITRE's ATT&CK. — want a quick lab outline?
, so many courses are still “not just collecting IOCs” in name only. If you want Q4 2025 tradecraft like BYOVD, DLL sideloading, and indirect syscalls, check out Open Threat Research University’s detection engineering labs — you pivot from Ghidra/IDA findings into Sigma/YARA and validate against ATT&CK with their emulation content: https://university.openthreatresearch.com. Caveat: it’s lighter on formal reversing than SANS, so you’ll want your own Windows lab to stress BYOVD safely — do you need instructor-led or self-paced?