{"repo":"SigmaHQ/sigma","free":true,"listed":false,"github":"https://github.com/SigmaHQ/sigma","clone":"git clone https://github.com/SigmaHQ/sigma.git","description":"Main Sigma Rule Repository","language":"Python","stars":10899,"topics":["security","monitoring","siem","logging","signatures","elasticsearch","splunk","ids","sysmon"],"license":null,"category":"security-tools","readme_excerpt":"Sigma - Generic Signature Format for SIEM Systems Welcome to the Sigma main rule repository. The place where detection engineers, threat hunters and all defensive security practitioners collaborate on detection rules. The repository offers more than 3000 detection rules of different type and aims to make reliable detections accessible to all at no cost. Currently the repository offers three types of rules: Generic Detection Rules - Are threat agnostic, their aim is to detect a behavior or an implementation of a technique or procedure that was, can or will be used by a potential threat actor. Threat Hunting Rules - Are broader in scope and are meant to give the analyst a starting point to hunt for potential suspicious or malicious activity Emerging Threat Rules - Are rules that cover specific threats, that are timely and relevant for certain periods of time. These threats include specific APT campaigns, exploitation of Zero-Day vulnerabilities, specific malware used during an attack,...etc. Compliance Rules - Are rules that help you identify compliance violations based on well known security frameworks such as CIS Controls, NIST, ISO 27001,...etc. Placeholder Rules - Are rules that get their final meaning at conversion or usage time of the rule. Explore Sigma To start exploring the Sigma ecosystem, please visit the official website sigmahq.io What is Sigma Sigma is a generic and open signature format that allows you to describe relevant log events in a straightforward manner. ","default_branch":null,"files":null,"tree":[],"storefront":"/r/SigmaHQ","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/SigmaHQ/sigma/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}