The Sigma command line interface based on pySigma
☆177Feb 5, 2026Updated 3 weeks ago
Alternatives and similar repositories for sigma-cli
Users that are interested in sigma-cli are comparing it to the libraries listed below
Sorting:
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆532Feb 15, 2026Updated last week
- pySigma Elasticsearch backend☆64Feb 19, 2026Updated last week
- pySigma Splunk backend☆41Feb 19, 2026Updated last week
- Sigma rule specification☆172Feb 5, 2026Updated 3 weeks ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆86Dec 17, 2025Updated 2 months ago
- Converts Sigma detection rules to a Splunk alert configuration.☆12Jul 1, 2021Updated 4 years ago
- pySigma Cookiecutter backend template☆24Sep 17, 2025Updated 5 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆92Nov 3, 2025Updated 3 months ago
- Ansible playbook to convert Sigma rules to ElastAlert rules☆10Feb 5, 2021Updated 5 years ago
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆12Sep 17, 2025Updated 5 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆785Updated this week
- Legacy Sigma Tools (sigmac etc.)☆16May 7, 2023Updated 2 years ago
- An opensource sigma conversion tool built using pysigma☆160Feb 9, 2026Updated 2 weeks ago
- 🐍 High-performance, multi-threaded YARA & IOC scanner☆265Feb 9, 2026Updated 2 weeks ago
- Resources To Learn And Understand SIGMA Rules☆182Feb 14, 2023Updated 3 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆159Mar 10, 2025Updated 11 months ago
- Knowing which rule should trigger according to the redcannary test☆11Nov 23, 2024Updated last year
- Detection Ideas & Rules repository.☆178Sep 10, 2021Updated 4 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Aug 6, 2022Updated 3 years ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆52Sep 1, 2023Updated 2 years ago
- A repository of my own Sigma detection rules.☆163Nov 25, 2025Updated 3 months ago
- Main Sigma Rule Repository☆10,145Feb 19, 2026Updated last week
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆74Jan 26, 2022Updated 4 years ago
- Investigate suspicious activity by visualizing Sysmon's event log☆431Dec 22, 2023Updated 2 years ago
- A repository to share publicly available Velociraptor detection content☆196Updated this week
- Log Entry to Sigma Rule Converter☆107Mar 3, 2022Updated 3 years ago
- Klara docker compose☆11May 19, 2020Updated 5 years ago
- ☆17Oct 13, 2025Updated 4 months ago
- Documentation and scripts to properly enable Windows event logs.☆672Oct 3, 2025Updated 4 months ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆612Dec 8, 2025Updated 2 months ago
- Windows Events Attack Samples☆2,515Jan 24, 2023Updated 3 years ago
- Sysmon configuration file template with default high-quality event tracing☆573Jan 21, 2026Updated last month
- Event Tracing For Windows (ETW) Resources☆417Oct 30, 2025Updated 4 months ago
- Scanner for certain IoCs☆11Jan 29, 2025Updated last year
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Aug 10, 2022Updated 3 years ago
- SigmaHQ pySigma CrowdStrike processing pipeline☆27Nov 30, 2025Updated 3 months ago
- A Splunk app to use MISP in background☆113Jan 8, 2026Updated last month
- Rules generated from our investigations.☆204Jun 17, 2025Updated 8 months ago
- A repository of curated datasets from various attacks☆726Feb 20, 2026Updated last week