1. What Sigma Solves for Defenders
Sigma is a generic rule format for detection engineering that helps defenders write and share detections in a portable way across SIEM and analytics platforms.
Sigma fits the "Detection rule format / detection-as-code" role in this course. Treat it as one tool in a workflow, not as a complete answer by itself. The key question is what decision quality it improves for a defender.
Before using Sigma, define the operational question first (triage, validation, exposure review, monitoring, forensics, or documentation). Tool selection should follow the question, not the other way around.