A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
-
Updated
May 30, 2026 - Python
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents. 768 rules across 10 categories; merged into Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H, FINOS & SigmaHQ. MIT-licensed.
Elemental - An ATT&CK Threat Library
Mapping of open-source detection rules and atomic tests.
IOK (Indicator Of Kit) is an open source language and ruleset for detecting phishing threat actor tools and tactics
Resources To Learn And Understand SIGMA Rules
BlackBerry Threat Research & Intelligence
A pySigma wrapper and langchain toolkit for automatic rule creation/translation
S2AN - Mapper of Sigma/Suricata Rules/Signatures ➡️ MITRE ATT&CK Navigator
A production-grade SIEM/XDR platform for 1M+ EPS ingestion with sub-15ms detection latency. Built with C++, Go, and Python. Features DPDK capture, ONNX ML inference, Sigma rules, eBPF monitoring, and SOAR.
Effort to list and aggregate known malicious Google Chrome Extension IDs
Sigma detection rules for hunting with the threathunting-keywords project
Open-source security platform for AI agents -- audits skills before install, monitors 24/7, shares threat intelligence across all users. | AI Agent 開源安全平台 -- 安裝前審計 skill、24/7 即時監控、社群共享威脅情報。
Complete Claude skills toolkit for professional malware analysis. 5 specialized skills covering triage, dynamic analysis, detection engineering, and reporting. Works with REMnux/FlareVM offline environments.
MCP server with 55 security intelligence tools — CVE/KEV, MITRE ATLAS+D3FEND, Sigma detection rules, email security posture (SPF/DMARC), domain & web intel, threat intel.
Open source HIDS tailored for Microsoft Windows and Active Directory
Framework definitions that allow to build a custom SIEM.
ESLint-style linter for Sigma detection rules. Validates against Sigma 2.1.0, scores rules across six quality dimensions, emits stable rule IDs.
Zero-touch pipeline that turns newly weaponized CVEs from the CISA Known Exploited Vulnerabilities (KEV) catalog into production-ready Sigma detection rules, automatically, every week.
Add a description, image, and links to the sigma-rules topic page so that developers can more easily learn about it.
To associate your repository with the sigma-rules topic, visit your repo's landing page and select "manage topics."