Security Tools

⚒️ Sigma Forge

Everyone translates rules into the SIEM. This does the opposite: you start from the event in front of you and walk out with the rule written. Paste a real event, tick what defines the malicious behaviour, and take away the Sigma rule plus its query in five dialects.

1 · Raw log 2 · Fields 3 · Sigma rule 4 · KQL / SPL / Lucene / EQL / Wazuh
Samples:

Want to check whether your rule really catches without flooding you with false positives? Test it against a log stream in the Sigma Detection Lab.