Skip to main content
SIEM-OPERATIONS5 MIN READ

Write a Sigma-style detection from behavior

Draft a portable SIEM detection by defining behavior, logsource, selections, condition, false positives, and validation.

Draft a SIEM detection for Office launching encoded PowerShell without relying only on a vendor hash or domain. Behavior -> Logsource -> Selection -> Condition -> False positives -> Validation The common trap is writing a keyword search for powershell -enc and shipping it with no parent process, no logsource assumption, and no false-positive note. Define behavior Suspicious behavior: Microsoft Office process spawns PowerShell with encoded command, hidden window, download cradle, or script block network retrieval. Behavior first keeps the detection durable when hashes and domains rotate. Declare logsource Required source: Windows process creation with parent and command line. Optional…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us