SigmaHQ Ecosystem

Ecosystem

The tools, backends, and pipelines that power the Sigma detection ecosystem. Convert rules to any SIEM or log analytics platform with pySigma.

Core Tools

Backends

29

Convert Sigma rules to platform-native query languages

Carbonblack

carbonblack

Stable

Carbon Black backend that supports queries for both Enterprise EDR (fka Threat Hunter) and EDR (fka Response)

GitHub

Cortex XDR

cortexxdr

Stable

Cortex XDR backend that generates XQL queries.

GitHub

CrowdStrike

crowdstrike

Stable

CrowdStrike Logscale backend and pipelines for CrowdStrike Falcon platform and Falcon Data Replicator (FDR) logs.

GitHub

Dictquery

dictquery

Stable

DictQuery backend to convert sigma to dictquery query strings

GitHub

Elasticsearch

elasticsearch

Stable

Elasticsearch backend converting into Lucene, ES|QL (with correlations) and EQL queries, plain, embedded into DSL or as Kibana NDJSON.

event count correlationvalue count correlationtemporal correlation
GitHub

Ibm QRadar AQL

ibm-qradar-aql

Stable

IBM QRadar backend for conversion into AQL queries. Contains mappings for fields and logsources

GitHub

Insightidr

insightidr

Stable

Rapid7 InsightIDR backend that generates LEQL queries.

GitHub

Kusto

kusto

Stable

Kusto Query Language (KQL) backend and pipeline for conversion of log sources with Sysmon field schema to Microsoft Advanced Hunting Queries

GitHub

Logpoint

logpoint

Stable

Logpoint Pysigma Backend

GitHub

Grafana Loki

loki

Stable

Loki backend for conversion into Loki LogQL queries (plain and ruler YAML for alerts) and pipelines with mappings for Grafana and promtail Sysmon data.

event count correlationvalue count correlation
GitHub

OpenSearch

opensearch

Stable

Opensearch backend converting into Lucene queries and Opensearch alerting rules.

GitHub

Panther

panther

Stable

Panther backend

GitHub

QRadar

qradar

Stable

IBM QRadar backend for conversion into AQL and extension packages.

GitHub

Sentinelone

sentinelone

Stable

SentinelOne backend that generates Deep Visibility queries.

GitHub

Sentinelone Pq

sentinelone-pq

Stable

SentinelOne backend that generates PowerQuery queries.

GitHub

SPLunk

splunk

Stable

Splunk backend for conversion into SPL and tstats data model queries as plain queries and savedsearches.conf

event count correlationvalue count correlationtemporal correlation
GitHub

Uberagent

uberagent

Stable

uberAgent backend

GitHub

Datadog

datadog

Testing

Datadog Cloud SIEM backend and pipeline for conversion of log sources to Datadog Query Syntax

GitHub

Golangexpr

golangexpr

Testing

Golang Expr Backend

GitHub

Hawk

hawk

Testing

HAWK.io MDR backend and pipeline for conversion of log sources to HAWK.io BETree queries.

GitHub

Netwitness

netwitness

Testing

NetWitness Backend that generates application rules

GitHub

Powershell

powershell

Testing

PowerShell backend converting into PowerShell queries.

GitHub

SQLite

sqlite

Testing

SQLite and Zircolite backend

GitHub

Surrealql

surrealql

Testing

SurrealQL Backend

GitHub

Ala Socprime

ala-socprime

Dev

Azure Log Analytics backend with Windows log support maintained by SOC Prime.

GitHub

Quickwit

quickwit

Dev

Quickwit Backend

GitHub

Secops

secops

Dev

Google SecOps (formally Chronicle) backend and pipeline for conversion of Sigma Rules to SecOps Unified Data Model (UDM) searches and YARA-L 2.0 detection rules

GitHub

Stix

stix

Dev

STIX backend converting into plain STIX queries. Contains mappings for STIX 2.0 and STIX Shifter taxonomies.

GitHub

Trellix_helix

trellix_helix

Dev

Trellix Helix Backend

GitHub

Pipelines

5

Field mappings and log source normalization

Need more pipelines?

The community pipelines repository is your next stop. Contribute your own or request new ones!

Community Pipelines