Found 812 repositories(showing 30)
SigmaHQ
Main Sigma Rule Repository
wagga40
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
SigmaHQ
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)
mdecrevoisier
Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques
Elemental-attack
Elemental - An ATT&CK Threat Library
Cybereason-Public
Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities
joesecurity
Sigma rules from Joe Security
Yamato-Security
Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.
The-DFIR-Report
Rules generated from our investigations.
krdmnbrk
Mapping of open-source detection rules and atomic tests.
phish-report
IOK (Indicator Of Kit) is an open source language and ruleset for detecting phishing threat actor tools and tactics
nasbench
Resources To Learn And Understand SIGMA Rules
SigmaHQ
Sigma rule specification
mbabinski
A repository of my own Sigma detection rules.
3CORESec
SIEGMA - Transform Sigma rules into SIEM consumables
tsale
Sigma rules to share with the community
P4T12ICK
Converts Sigma detection rules to a Splunk alert configuration.
northsh
Convert Sigma rules to SIEM queries, directly in your browser.
P4T12ICK
A Splunk App containing Sigma detection rules, which can be updated from a Git repository.
Neo23x0
Log Entry to Sigma Rule Converter
markuskont
Golang library that implements a sigma log rule parser and match engine.
blackberry
BlackBerry Threat Research & Intelligence
bradleyjkemp
A Go implementation and parser for Sigma rules.
P4T12ICK
Sigma Detection Rule Repository
InnerWarden
Autonomous open-source security agent for Linux (Apache-2.0). 40 eBPF hooks, 49 detectors, 47 correlation rules, 65 MITRE ATT&CK techniques, AI triage, behavioral DNA cross-IP tracking, mesh defense.
AttackIQ
A pySigma wrapper and langchain toolkit for automatic rule creation/translation
3CORESec
S2AN - Mapper of Sigma/Suricata Rules/Signatures ➡️ MITRE ATT&CK Navigator
Agent-Threat-Rule
Open detection standard for AI agent threats. Like Sigma, but for prompt injection, tool poisoning, and MCP attacks. Community-driven -- contributions welcome.
theflakes
Convert Sigma rules to Wazuh rules
dstaulcu
A Splunk app with saved reports derived from Sigma rules