← Threat Intel & Detection
Sigma
Open, shareable rule format for SIEM detections.
Sigma is a generic, vendor-neutral rule format for log-based detections, with a large community rule repository and converters to many SIEM query languages.
Why it's useful
Write a detection once and convert it for any SIEM.