A complete Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, MCP and LSP servers
☆151Oct 2, 2026Updated this week
Alternatives and similar repositories for rsigma
Users that are interested in rsigma are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account requi…☆496Updated this week
- ☆14Jun 15, 2026Updated 3 months ago
- Generate malware traces for detection tests☆19Updated this week
- Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.☆116Dec 3, 2025Updated 9 months ago
- pySigma Elasticsearch backend☆77Updated this week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Converts Sigma detection rules to a Splunk alert configuration.☆12Jul 1, 2021Updated 5 years ago
- syslog-ng metrics exporter☆16Sep 25, 2026Updated last week
- ☆59Dec 13, 2025Updated 9 months ago
- A simple tool designed to create Atomic Red Team tests with ease.☆66May 3, 2026Updated 4 months ago
- ☆18Sep 22, 2025Updated last year
- A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concret…☆62Updated this week
- Detection engineering template☆15Jul 24, 2025Updated last year
- Mapping of open-source detection rules and atomic tests.☆217Jul 15, 2026Updated 2 months ago
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆39May 22, 2026Updated 4 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- An opensource sigma conversion tool built using pysigma☆176Updated this week
- Official, curated detection content (Sigma, YARA, IOC packs) for the Rustinel endpoint detection engine.☆26Updated this week
- suspect is a simple bash triage tool☆19Aug 30, 2018Updated 8 years ago
- 🛡️ SIGMA Detection Engineering Platform A comprehensive AI-powered detection engineering platform for security teams to explore MITRE AT…☆46Jun 28, 2025Updated last year
- Some stuff for PHD2021☆14May 21, 2025Updated last year
- A public repository of quality research on cyber attack techniques. This is the backend for the Technique Research Report (TRR) Library.☆31Sep 1, 2026Updated last month
- ☆114Dec 9, 2025Updated 9 months ago
- Super light, super fast, unlimited search idea☆26Aug 3, 2025Updated last year
- Your Browser-based EVTX Companion☆124Jul 21, 2026Updated 2 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Registry timestamp manipulation☆17Feb 26, 2014Updated 12 years ago
- Automate the conversion and deployment of Sigma Rules to Grafana Alerting via GitHub Actions☆19Sep 24, 2026Updated last week
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Feb 15, 2022Updated 4 years ago
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆224Updated this week
- BlueSploit is a DFIR framework with the main purpose being to quickly capture artifacts for later review.☆33Jan 1, 2020Updated 6 years ago
- ☆147Aug 10, 2026Updated last month
- Yara rules☆22Mar 27, 2023Updated 3 years ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆56Updated this week
- ☆46Nov 28, 2025Updated 10 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Sigma rule specification☆210Sep 25, 2026Updated last week
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated 2 months ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆28Dec 5, 2025Updated 9 months ago
- YARA Rule Strings Statistics Calculator and Malware Research Helper☆14Jul 24, 2021Updated 5 years ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆598Updated this week
- Cobaltstrike UDRL with memory evasion☆14May 16, 2024Updated 2 years ago
- Epimitheus is a tool that uses graphical database Neo4j for Windows Events visualization.☆19Mar 13, 2022Updated 4 years ago