Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms.
sigmahq/sigma की मुख्य विशेषताएं हैं: Query Translation Layers, SIEM, SIEM Rule Converters, Detection Engineering, Security Event Correlation, Security Analytics Platforms, Schema Definition Languages, Log Field Mappings।
sigmahq/sigma के ओपन-सोर्स विकल्पों में शामिल हैं: elastic/detection-rules — This project is a detection-as-code framework providing a library of security monitoring rules and predefined… neo23x0/sigma — Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It… holistics/dbml — DBML is a domain-specific language and schema definition language used for documenting database architecture and… containers/podman-desktop — Podman Desktop is a graphical user interface for managing container images, pods, and volumes across multiple… misp/misp — MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing… mdx-editor/editor — This project is a React-based rich text editor designed for authoring and managing markdown documents through a visual…
This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base
Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems
DBML is a domain-specific language and schema definition language used for documenting database architecture and design. It provides a human-readable text format for defining database tables, columns, and relationships in a standardized way. The project functions as a relational schema parser and SQL schema generator. It transforms declarative design specifications into an abstract syntax tree for programmatic manipulation and converts these definitions into executable SQL statements across various database dialects. The system covers relational data modeling, database schema design, and arc
Podman Desktop is a graphical user interface for managing container images, pods, and volumes across multiple container engines and Kubernetes clusters. It serves as a container engine orchestrator for installing, configuring, and updating engines, as well as a deployment dashboard for connecting to Kubernetes environments and switching cluster contexts. The application is an extensible developer tool that utilizes a plugin system to allow users to add new features and orchestration capabilities through third-party modules. The tool provides a resource dashboard for local container managemen