Sigma rules, ready for your SIEM.

Curated + in-house forged Sigma detection rules, deduplicated against the public Sigma corpus and signed, delivered as raw Sigma AND pre-converted for your SIEM. Paste the query, it detects.

7 000+
Sigma rules
4 SIEM
Splunk · Sentinel · Elastic · QRadar
.yml + requêtes
raw + SPL / KQL / ECS / AQL
Ed25519
signed, continuous updates

What we added recently

A living feed: here is the coverage added to it, dated.

  • +592 règles
  • +51 règles
  • +67 règles
  • +9 règles
  • +173 règles

Raw Sigma, and already translated for your tool.

Sigma (.yml)

The rules in the open Sigma format, convert with your own pySigma, or use as-is.

Splunk (SPL)

Pre-converted to SPL queries, ready to paste into Splunk.

Sentinel (KQL)

Converted to KQL for Microsoft Sentinel / Defender.

Elastic (ECS) & QRadar (AQL)

Converted for Elastic (ECS), CrowdStrike (LogScale), Panther and QRadar (AQL), the 4 major SIEMs covered.

Curated from the public Sigma corpus (DRL) + deduplicated permissive sources + exclusive in-house forged rules. The SIEM conversions are included under the same key.

See the full coverage

Try before you buy: free demo pack

A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.

Download the demo pack .zip

The right format for every SIEM.

Sigma .ymlyour own pySigma, any backend, archival
SPLSplunk
KQLMicrosoft Sentinel / Defender
ECSElastic Security
AQLIBM QRadar

Not a mirror of the public Sigma corpus.

01
Curated & deduplicated

Deduplicated against the public Sigma corpus so you don’t pay twice for the same rule.

02
An investigation playbook per rule

Every rule ships with a CACAO 2.0 investigation playbook (OASIS standard): confirm, pivot, scope, rule out false positives, respond — generated deterministically from the rule’s own facts (ATT&CK, D3FEND), 0 AI. No rule aggregator does this.

03
In-house rules

Exclusive in-house forged rules, not in the public corpus, on recent threats.

04
SIEM ready-to-paste

Queries pre-converted for Splunk, Sentinel, Elastic, CrowdStrike, Panther and QRadar.

05
Clean, verified licensing

Permissive upstream (DRL / Apache / CC0) is redistributable under its own license, attribution kept; our in-house rules and the compilation stay proprietary (EULA, subscriber use).

06
Ed25519-signed

The feed is signed; you verify its integrity before applying it.

07
One script, one cron

One sync script, your key, the frequency you want.

Where do the rules come from?

From the public Sigma corpus (DRL license) and permissive sources (Apache / CC0), aggregated and deduplicated, plus our own in-house forged rules. No non-commercial source enters: the permissive upstream stays redistributable under its own license, while our 355 in-house rules and the curated compilation are proprietary (EULA).

Are the SIEM conversions included?

Yes. Every rule ships as raw Sigma AND pre-converted for Splunk (SPL), Sentinel (KQL), Elastic (ECS), CrowdStrike (LogScale), Panther and QRadar (AQL), under the same key, at no extra cost.

What if I also need YARA?

YARA is sold separately (€349/mo), or take the Sigma + YARA bundle at €549/mo (−21%): both feeds under one key.

Can I use it as an MSSP / redistribute it?

You use it within your organization, including to run detection on behalf of your clients. What you can’t do: resell or redistribute the pack as-is. The permissive upstream components (DRL / Apache / CC0) remain redistributable under their own license, attribution kept; our 355 in-house rules and the curated compilation are proprietary (EULA, use by the subscribing organization).

Ready to power your SIEM?

Annual subscription. Instant key. Cancel anytime.

€349 / month, billed annually €4,188 excl. tax

Also need YARA? Get the Sigma + YARA bundle, €549/mo (−21%)

What this pack does not cover

What we do not cover, we tell you

No one detects 100%, and a feed that claims otherwise burns out your analyst. Anything that does not compile on the real engine, or lights up on a benign corpus, never reaches the pack. What a rule cannot see, we show as a gap rather than paper over it. And by default the agent observes and proposes, acting only after human validation (human-in-the-loop). You buy signal, not volume.

Detection that holds up in front of the auditor

The question is no longer only “can I detect?” but “can I prove it?”. Every subscription ships with the compliance layer, at no extra cost.

Design coverage, not a certification nor a real-time measurement: it evidences that the catalogue addresses the requirement, your CISO validates compliance.

Detection guides

The method behind the pack, on our blog.

2026-09-05
Detecting Phobos: What a Ransomware Actually Does, and the Rule That Stops It

We detonated a live Phobos sample. Here is what it does, deleting shadow copies, killing the firewall, and the Sigma rule that catches it, validated across multiple samples with zero false positives.

2026-08-23
Detecting Shadow AI: Finding Unsanctioned AI Use in Your Logs

Shadow AI is shadow IT's faster, leakier cousin. This guide covers what it is, why it is a real risk, and — the part nobody writes about — how to actually detect unsanctioned AI use in your network, proxy and endpoint logs, with a working Sigma rule.

2026-08-23
The DGFiP Breach: An Attack No Antivirus Could Ever Flag

Valid credentials, internal VPN, business application: the French tax authority breach shows why behavioural detection beats signatures every time.

2026-08-23
Open Source SIEM in 2026: An Honest Comparison of Wazuh, Elastic, Security Onion and Graylog

Wazuh, Elastic/Security Onion, Graylog, OpenSearch — a genuinely balanced comparison of free and open-source SIEM options for SMBs, with real resource requirements, a Sigma-ingestion table, and the part every vendor page skips: what happens after install day.

2026-08-08
Proven Detection, Not Scraped Rules: What Sets the ThreatClaw Feed Apart

A rule feed is not worth its rule count. It is worth the proof that the rules fire and what you do when they trigger. Tested on real engines, false-positive-proven, signed, and every rule ships an investigation playbook wired to our other engines.

2026-07-24
SharePoint CVE-2026-45659: The Deserialization That Leads to Warlock Ransomware

Deserialization of untrusted data yields RCE on on-premise SharePoint. In the KEV, exploited by Storm-2603. Here is the Sigma rule on w3wp and Nuclei detection.