A complete Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, MCP and LSP servers
☆120Aug 3, 2026Updated this week
Alternatives and similar repositories for rsigma
Users that are interested in rsigma are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSO…☆445Updated this week
- ☆15Jun 15, 2026Updated last month
- Generate malware traces for detection tests☆16Updated this week
- Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.☆114Dec 3, 2025Updated 8 months ago
- pySigma backend for generating Grafana Loki/LogQL rules☆54Updated this week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- pySigma Elasticsearch backend☆73Jul 26, 2026Updated last week
- Converts Sigma detection rules to a Splunk alert configuration.☆12Jul 1, 2021Updated 5 years ago
- A simple tool designed to create Atomic Red Team tests with ease.☆65May 3, 2026Updated 3 months ago
- syslog-ng metrics exporter☆16Updated this week
- ☆58Dec 13, 2025Updated 7 months ago
- Official, curated detection content (Sigma, YARA, IOC packs) for the Rustinel endpoint detection engine.☆23Updated this week
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆37May 22, 2026Updated 2 months ago
- ☆17Sep 22, 2025Updated 10 months ago
- A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concret…☆57Mar 5, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Mapping of open-source detection rules and atomic tests.☆215Jul 15, 2026Updated 2 weeks ago
- Automate the conversion and deployment of Sigma Rules to Grafana Alerting via GitHub Actions☆18Updated this week
- Detection engineering template☆15Jul 24, 2025Updated last year
- An opensource sigma conversion tool built using pysigma☆174Updated this week
- suspect is a simple bash triage tool☆19Aug 30, 2018Updated 7 years ago
- 🛡️ SIGMA Detection Engineering Platform A comprehensive AI-powered detection engineering platform for security teams to explore MITRE AT…☆45Jun 28, 2025Updated last year
- Some stuff for PHD2021☆14May 21, 2025Updated last year
- A public repository of quality research on cyber attack techniques. This is the backend for the Technique Research Report (TRR) Library.☆28Jul 22, 2026Updated last week
- ☆115Dec 9, 2025Updated 7 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆196Updated this week
- ☆143Jun 18, 2026Updated last month
- Super light, super fast, unlimited search idea☆27Aug 3, 2025Updated last year
- Your Browser-based EVTX Companion☆123Jul 21, 2026Updated last week
- Registry timestamp manipulation☆17Feb 26, 2014Updated 12 years ago
- Lightweight open-core SIEM in Rust — ClickHouse for logs, Postgres for state.☆68Updated this week
- LLM benchmark results for THOR forensic finding triage quality☆25Updated this week
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Feb 15, 2022Updated 4 years ago
- BlueSploit is a DFIR framework with the main purpose being to quickly capture artifacts for later review.☆33Jan 1, 2020Updated 6 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Yara rules☆21Mar 27, 2023Updated 3 years ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆56Jul 27, 2026Updated last week
- ☆46Nov 28, 2025Updated 8 months ago
- Sigma rule specification☆199Jun 9, 2026Updated last month
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated 3 weeks ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆26Dec 5, 2025Updated 7 months ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆581Updated this week