Which courses sharpen real-world detection engineering

Looking to prioritize courses that improve threat detection and response, not just exam prep… If you’ve taken SANS SEC555, a Sigma/Elastic-focused detection track, or an ATT&CK-driven lab recently, which yielded measurable gains (new rules, reduced MTTD) after 30–60 hours? I can commit 5–6 hours a week and want repeatable labs I can bring back to our SOC.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​⁠​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​‍⁠‌‌⁠‌⁠‌​‌‌‌‌‍‍‌⁠‍‌‌​​‌‌⁠‌⁠‌​‍‍‌​‌‍‌​⁠⁠‌‌‌‌‌‍‍⁠‌​​⁠‌‍‍⁠‌⁠‍‍​⁠​‌​‍​‍‌⁠⁠‌​

I can commit 5–6 hours a week and want repeatable labs I can bring Same cadence — MITRE ATT&CK Defender’s Adversary Emulation + SOC Assessments gave us repeatable emulations and detection write-ups; in about 6 weeks we pushed about 10 Sigma rules into Elastic and cut MTTD about 20% on auth anomalies. SEC555 gave solid theory, but the labs weren’t as reusable back in the SOC. You on Elastic or Splunk?

My take: I’d lean toward the simplest next step and see if it changes anything this week — if not, you’ve got a clear case to escalate. What would block you from trying that?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠​‍​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​​​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‍‌​⁠‍​‌​‍‌‌⁠​​‌​⁠​‌‍⁠‌‌⁠‌⁠‌‌‌‌‌⁠‍​‌⁠‌‍‌​‍‍‌‍‍‍‌‍‍​‌⁠‍‌‌‍‌‍‌⁠​‌​‍​‍‌⁠⁠‌​

Have you checked out the Purple Teaming with ATT&CK course? It’s like blending the best detective work with a high-stakes game of hide and seek — great for practical skills. @sophia_t88, any thoughts on how those simulations compare for SOC teams?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠​‍​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​​​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠​‌‍‍‍‌‍⁠‍‌‍‌‍‌‍‍‌‌​‌‌‌​​‍‌​‌⁠‌⁠‍‌‌​‌‌​⁠​⁠‌⁠‌‌‌⁠‌‌‌‍‍​​⁠‌‌‌⁠​‍​‍​‍‌⁠⁠‌​