{"repo":"Nebulock-Inc/macos-coresigma","free":true,"listed":false,"github":"https://github.com/Nebulock-Inc/macos-coresigma","clone":"git clone https://github.com/Nebulock-Inc/macos-coresigma.git","description":"coreSigma is a macOS ESF & UL telemetry pipeline, detection, and threat hunting app for security analysis, using Sigma and Sigma backend for rule creation and translation.","language":"Python","stars":14,"topics":["cybersecurity","detection-engineering","elasticsearch","macos","security-analysis","security-pipeline","security-tools","siem","sigma-rules","sigmahq"],"license":"MIT","category":"security-tools","readme_excerpt":"macOS CoreSigma macOS CoreSigma is a comprehensive Sigma-based detection framework for macOS Endpoint Security Framework (ESF) and Unified Logging (UL) telemetry. It enables security teams to leverage the Sigma rule format for advanced macOS threat detection and hunting. Overview CoreSigma provides: - 57 Detection Rules - 38 ESF rules and 19 UL rules covering process execution, file events, authentication, privilege escalation, persistence, and more - ECS-Compatible Data Collection - Collectors that normalize ESF/UL events to Elastic Common Schema (ECS) format - Intelligent Filtering - Reduces log volume by 98.5% while preserving 100% security-relevant events - Kibana Dashboards - Pre-built security dashboards for real-time monitoring - pySigma Integration - Compatible with the ecs macos esf pipeline in pySigma-backend-elasticsearch Related Projects - pySigma-backend-elasticsearch - The pySigma backend with ecs macos esf pipeline (PR #171) - sigma-specification - Sigma taxonomy with macOS ESF logsource (PR #25) Quick Start Prerequisites - macOS 11.0+ (Big Sur or later) - Python 3.9+ - Elasticsearch 8.x and Kibana - Root/sudo access (required for ESF collection via eslogger ) - Full Disk Access permission for Terminal (required for ESF collector) Important : The ESF collector uses Apple's Endpoint Security Framework which requires Full Disk Access. Grant this in System Settings → Privacy & Security → Full Disk Access for your terminal app (Terminal.app, iTerm2, etc.). See INST","default_branch":null,"files":null,"tree":[],"storefront":"/r/Nebulock-Inc","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Nebulock-Inc/macos-coresigma/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}