Security Tools
⚒️ Sigma Forge
Everyone translates rules into the SIEM. This does the opposite: you start from the event in front of you and walk out with the rule written. Paste a real event, tick what defines the malicious behaviour, and take away the Sigma rule plus its query in five dialects. What does a Windows event log? Browse the Windows Event ID reference. Already have a rule? Run it through the detection linter.
Want to check whether your rule really catches without flooding you with false positives? Test it against a log stream in the Sigma Detection Lab.
Only the selected configuration is transferred within this tab, for up to 10 minutes. The log is not sent to the server. The bench uses synthetic samples and rejects unsupported conditions.