Writing Sigma Rules

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with Hayabusa or Chainsaw. Use when translating threat intel into vendor-agnostic detection logic, building a detection-as-code pipeline around Sigma, reviewing or tuning existing Sigma rules, or converting rules across SIEM backends.

trilwu a3c4d7b 15.9 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/writing-sigma-rules commit a3c4d7b136

Frequently asked questions

npx skillmds add trilwu/writing-sigma-rules