
Sigma
Sigma is a free open signature format used to write and share platform-neutral detection rules across SIEM tools for detection engineers and threat hunters.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Reviewed
- Last reviewed 6 October 2026
What it is
An open, structured way to describe suspicious log events in YAML so that one rule can convert into queries for many different monitoring systems.
What it helps with
- Writing a detection once and converting it to several query languages
- Sharing community reviewed rules for threats, hunting, and compliance
- Keeping detection logic readable and tied to no single platform
Who it's for
Detection engineers, threat hunters, and SOC analysts who build and share log-based detections.
Worth knowing
Rules are converted with the separate sigma-cli and pySigma tooling. The rule set uses the Detection Rule License, which is permissive but not OSI approved, while the specification is public domain.
Are there rules for brand-new threats?
Yes. Emerging threat rules target specific campaigns and recently exploited vulnerabilities.
Is the format itself versioned?
Yes. The specification is maintained separately and carries its own version number.
How often do new rules land?
New rule packages are published on a regular schedule.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.