# Sigma

> Create Sigma detection rules for SIEM log-based detection

- Skill: `majiayu000/sigma` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds add majiayu000/sigma`
- Raw SKILL.md: https://api.skillmd.com/api/skills/majiayu000/sigma/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: majiayu000 (https://skillmd.com/u/majiayu000)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/majiayu000/sigma

---


# Sigma Rule Creation

Create SIEM-agnostic detection rules:
- Process execution patterns
- Registry modifications
- Network connections
- Authentication events
- File operations

## Required Context
1. **Pattern**: What to detect (TTP, behavior, IOC)
2. **Log Source**: Sysmon, Security, EDR, etc.
3. **Context**: False positive considerations

## Output
- Sigma YAML rule
- SIEM conversion commands (Splunk, Elastic, Sentinel)

## Sigma Conversion
```bash
sigma convert -t splunk rule.yml
sigma convert -t elasticsearch rule.yml
sigma convert -t azure-sentinel rule.yml
```

## Example
```
/sigma
Pattern: Office spawning PowerShell with encoded commands
Source: Sysmon Event 1
```

