Sigma rules, ready for your SIEM.
Curated + in-house forged Sigma detection rules, deduplicated against the public Sigma corpus and signed, delivered as raw Sigma AND pre-converted for your SIEM. Paste the query, it detects.
What we added recently
A living feed: here is the coverage added to it, dated.
- +592 règles
- +51 règles
- +67 règles
- +9 règles
- +173 règles
Raw Sigma, and already translated for your tool.
The rules in the open Sigma format, convert with your own pySigma, or use as-is.
Pre-converted to SPL queries, ready to paste into Splunk.
Converted to KQL for Microsoft Sentinel / Defender.
Converted for Elastic (ECS), CrowdStrike (LogScale), Panther and QRadar (AQL), the 4 major SIEMs covered.
Curated from the public Sigma corpus (DRL) + deduplicated permissive sources + exclusive in-house forged rules. The SIEM conversions are included under the same key.
A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.
↓ Download the demo pack .zipThe right format for every SIEM.
Not a mirror of the public Sigma corpus.
Deduplicated against the public Sigma corpus so you don’t pay twice for the same rule.
Every rule ships with a CACAO 2.0 investigation playbook (OASIS standard): confirm, pivot, scope, rule out false positives, respond — generated deterministically from the rule’s own facts (ATT&CK, D3FEND), 0 AI. No rule aggregator does this.
Exclusive in-house forged rules, not in the public corpus, on recent threats.
Queries pre-converted for Splunk, Sentinel, Elastic, CrowdStrike, Panther and QRadar.
Permissive upstream (DRL / Apache / CC0) is redistributable under its own license, attribution kept; our in-house rules and the compilation stay proprietary (EULA, subscriber use).
The feed is signed; you verify its integrity before applying it.
One sync script, your key, the frequency you want.
Where do the rules come from?
From the public Sigma corpus (DRL license) and permissive sources (Apache / CC0), aggregated and deduplicated, plus our own in-house forged rules. No non-commercial source enters: the permissive upstream stays redistributable under its own license, while our 355 in-house rules and the curated compilation are proprietary (EULA).
Are the SIEM conversions included?
Yes. Every rule ships as raw Sigma AND pre-converted for Splunk (SPL), Sentinel (KQL), Elastic (ECS), CrowdStrike (LogScale), Panther and QRadar (AQL), under the same key, at no extra cost.
What if I also need YARA?
YARA is sold separately (€349/mo), or take the Sigma + YARA bundle at €549/mo (−21%): both feeds under one key.
Can I use it as an MSSP / redistribute it?
You use it within your organization, including to run detection on behalf of your clients. What you can’t do: resell or redistribute the pack as-is. The permissive upstream components (DRL / Apache / CC0) remain redistributable under their own license, attribution kept; our 355 in-house rules and the curated compilation are proprietary (EULA, use by the subscribing organization).
Ready to power your SIEM?
Annual subscription. Instant key. Cancel anytime.
Also need YARA? Get the Sigma + YARA bundle, €549/mo (−21%)