awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
SigmaHQ avatar

SigmaHQ/sigma

0
View on GitHub↗
10,136 स्टार्स·2,549 फोर्क्स·Python·other·10 व्यूज़sigmahq.io↗

Sigma

Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms.

The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that generates coverage heatmaps by linking detection rule metadata to established security threat frameworks.

The system covers security log normalization, multi-stage attack correlation, and log-to-rule generation. It further supports the export of detection rules into threat intelligence platforms to centralize indicators and security logic.

Features

  • Query Translation Layers - Translates generic security detection rules into proprietary query languages for various SIEM and log management platforms.
  • SIEM - Converts standardized log-detection rules into proprietary query languages for various SIEM platforms.
  • SIEM Rule Converters - Translates standardized security detection signatures into search queries for various SIEM and logging platforms.
  • Detection Engineering - Uses a structured, standardized format to describe malicious behavior consistently across different log files.
  • Security Event Correlation - Identifies complex attack sequences by specifying patterns where multiple events trigger within a set timeframe.
  • Security Analytics Platforms - Maps generic event fields and correlation logic to the proprietary query languages of security data lakes.
  • Schema Definition Languages - Employs a standardized YAML-based language to define detection logic independently of specific logging platforms.
  • Log Field Mappings - Provides a translation layer that maps generic log fields to platform-specific identifiers across diverse data sources.
  • Log-to-Signature Generators - Automatically creates formal detection signatures by converting provided log entries into structured rules.
  • Framework Coverage Mapping - Associates detection rules with external security frameworks by scanning metadata tags to generate coverage heatmaps.
  • Multi-Backend Query Generators - Exports security detections into multiple different database and log management formats via a plugin-based converter.
  • Query Generation Patterns - Constructs complex search strings by iterating through logic operators defined in a standardized rule schema.
  • Plugin Systems - Provides a flexible plugin system for adding new security platform targets and customizing data conversion.
  • Coverage Heatmaps - Provides a utility to generate visual coverage heatmaps by linking detection rule metadata to established security threat frameworks.
  • Detection Coverage Heatmaps - Creates a visual heatmap of security coverage by mapping rule tags to threat frameworks.
  • Intermediate Representations - Implements an internal representation that bridges high-level detection logic and final backend-specific query formats.
  • Plugin-Based Architectures - Uses a modular plugin architecture to map generic detection signatures to target-specific query syntaxes.
  • Detection Rules and Analytics - Generic signature format for SIEM systems.
  • Log Analysis Tools - Generic signature format for SIEM detection rules.
  • Threat Intelligence - Standardized signature format for security information and event management.
  • Detection Content Libraries - Provides a universal, platform-agnostic format for detection content.
  • Advanced Threat Analysis - Generic signature format for log-based threat detection.
  • Signature Rules - Generic signature format for detecting malicious events in logs.

स्टार हिस्ट्री

sigmahq/sigma के लिए स्टार हिस्ट्री चार्टsigmahq/sigma के लिए स्टार हिस्ट्री चार्ट

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Start searching with AI

अक्सर पूछे जाने वाले प्रश्न

sigmahq/sigma क्या करता है?

Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms.

sigmahq/sigma की मुख्य विशेषताएं क्या हैं?

sigmahq/sigma की मुख्य विशेषताएं हैं: Query Translation Layers, SIEM, SIEM Rule Converters, Detection Engineering, Security Event Correlation, Security Analytics Platforms, Schema Definition Languages, Log Field Mappings।

sigmahq/sigma के कुछ ओपन-सोर्स विकल्प क्या हैं?

sigmahq/sigma के ओपन-सोर्स विकल्पों में शामिल हैं: elastic/detection-rules — This project is a detection-as-code framework providing a library of security monitoring rules and predefined… neo23x0/sigma — Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It… holistics/dbml — DBML is a domain-specific language and schema definition language used for documenting database architecture and… containers/podman-desktop — Podman Desktop is a graphical user interface for managing container images, pods, and volumes across multiple… misp/misp — MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing… mdx-editor/editor — This project is a React-based rich text editor designed for authoring and managing markdown documents through a visual…

Sigma के ओपन-सोर्स विकल्प

समान ओपन-सोर्स प्रोजेक्ट्स, जो Sigma के साथ साझा की गई सुविधाओं के आधार पर रैंक किए गए हैं।
  • elastic/detection-ruleselastic का अवतार

    elastic/detection-rules

    2,508GitHub पर देखें↗

    This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base

    Pythonthreat-detectionthreat-hunting
    GitHub पर देखें↗2,508
  • neo23x0/sigmaNeo23x0 का अवतार

    Neo23x0/sigma

    10,591GitHub पर देखें↗

    Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems

    Python
    GitHub पर देखें↗10,591
  • holistics/dbmlholistics का अवतार

    holistics/dbml

    3,520GitHub पर देखें↗

    DBML is a domain-specific language and schema definition language used for documenting database architecture and design. It provides a human-readable text format for defining database tables, columns, and relationships in a standardized way. The project functions as a relational schema parser and SQL schema generator. It transforms declarative design specifications into an abstract syntax tree for programmatic manipulation and converts these definitions into executable SQL statements across various database dialects. The system covers relational data modeling, database schema design, and arc

    JavaScriptdatabase-schemadbmldbx
    GitHub पर देखें↗3,520
  • containers/podman-desktopcontainers का अवतार

    containers/podman-desktop

    7,725GitHub पर देखें↗

    Podman Desktop is a graphical user interface for managing container images, pods, and volumes across multiple container engines and Kubernetes clusters. It serves as a container engine orchestrator for installing, configuring, and updating engines, as well as a deployment dashboard for connecting to Kubernetes environments and switching cluster contexts. The application is an extensible developer tool that utilizes a plugin system to allow users to add new features and orchestration capabilities through third-party modules. The tool provides a resource dashboard for local container managemen

    TypeScript
    GitHub पर देखें↗7,725
  • Sigma के सभी 30 विकल्प देखें→