Threat Hunting With Sigma Rules

Build and refine Sigma-based detections to identify malicious behavior across logs and telemetry. Use when creating detections, mapping ATT&CK techniques, and improving SOC hunting coverage.

nikopj01 Updated

File contents

Threat Hunting with Sigma Rules

Workflow

  1. Define hunting hypothesis and required telemetry sources.
  2. Select or create Sigma rules mapped to ATT&CK techniques.
  3. Validate against benign and malicious samples to reduce false positives.
  4. Tune filters, enrich context, and document response playbooks.
  5. Track coverage gaps and schedule iterative rule improvements.

nikopj01/codex-skills/tree/main/threat-hunting-with-sigma-rules commit 59c3401385

Frequently asked questions

npx skillmds@latest add nikopj01/threat-hunting-with-sigma-rules