Skip to content
hackingtools.ai
Sigma

Sigma

Sigma is a free open signature format used to write and share platform-neutral detection rules across SIEM tools for detection engineers and threat hunters.

0

0 upvotes · 0 downvotes

No ratings yet

Pricing
Free
Platforms
LinuxWindowsmacOS
Reviewed
Last reviewed 6 October 2026

What it is

An open, structured way to describe suspicious log events in YAML so that one rule can convert into queries for many different monitoring systems.

What it helps with

- Writing a detection once and converting it to several query languages
- Sharing community reviewed rules for threats, hunting, and compliance
- Keeping detection logic readable and tied to no single platform

Who it's for

Detection engineers, threat hunters, and SOC analysts who build and share log-based detections.

Worth knowing

Rules are converted with the separate sigma-cli and pySigma tooling. The rule set uses the Detection Rule License, which is permissive but not OSI approved, while the specification is public domain.

Are there rules for brand-new threats?
Yes. Emerging threat rules target specific campaigns and recently exploited vulnerabilities.

Is the format itself versioned?
Yes. The specification is maintained separately and carries its own version number.

How often do new rules land?
New rule packages are published on a regular schedule.

Discussion & reviews

0 comments

Your rating (optional)

0/4,000

No contributions yet. Be the first to review or comment.

← Back to directory