Building Detection Rules With Sigma

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.

theheavenlyd3mon 967cd29 4 files · 29.7 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/building-detection-rules-with-sigma commit 967cd29d50

Frequently asked questions

npx skillmds add theheavenlyd3mon/building-detection-rules-with-sigma