Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

SIGMA_Rules

This GitHub repo is operated and maintained by the Cybersecurity and Infrastructure Security Agency (CISA) of the United States Federal Government. The content of this GitHub repo is provided “as is” for informational purposes only and without any warranties or guarantees. Network defenders should evaluate this content and use as appropriate.

This repo provides a collection of Sigma detection rules for SIEM platforms to identify malicious or suspicious activity and potential threats. Network defenders reviewing this repo should evaluate the rules and modify as needed to align with their organization’s environment and specific hunt objectives. These rules support threat detection, threat hunting, incident response, and related cybersecurity activities. CISA started developing Sigma rules in 2023 to meet an industry demand. You may use a local Sigma installation or an online converter of your choice to convert the rules.

About

A collection of Sigma detection rules for SIEM platforms to identify malicious or suspicious activity and potential threats. Modify the rules as needed to align with your organization’s environment and specific hunt objectives. These rules support threat detection, threat hunting, incident response, and related cybersecurity activities.

Resources

Security policy

Stars

10 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors