

Is the BTLV CJDE Cert Worth It? feat. Tobias Castleberry
Tobias Castleberry joins Dispatch to answer a question: is a detection engineering certification actually worth it? With detection engineering certifications still few and far between, Tobias breaks down his experience taking the CJDE from the perspective of someone already doing the work. We get into the training, the labs, the exam, failing the first attempt, and what changed the second time around. But the bigger conversation is about what the certification gets right about detection engineering: it’s not just writing a rule. It’s understanding the threat, building coverage, testing it, tuning it, validating it, shipping it, and knowing when that detection has stopped doing its job. In this episode we get into: Why building a home lab helped Tobias turn curiosity into a repeatable detection engineering workflow The difference between getting a detection to fire in a lab and keeping it useful in the real world Tobias’s experience failing the exam on his first attempt and what he changed before passing Why practical exams can reveal something multiple choice tests can’t How Tobias uses Atomic Red Team, Caldera, Chainsaw, and Sysmon to break and validate his detections Why junior analysts may be better served by spending more time investigating real alerts before jumping into detection engineering Who the certification is actually for and who should probably wait What Tobias thinks could make the certification even better, especially around tuning, adversary emulation, and the full detection lifecycle The badge isn’t necessarily the point, it's the discipline that is, and this is what the cert validated. Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.
- Transcript














