OSS TanbouSign in with GitHub

A vendor-agnostic ruleset for sharing and evaluating log detections across SIEM platforms

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
11,152
Primary language
Python
License
Not determined
Repository last updated
Oct 4, 2026
On this page

Overview

Sigma is a specification and rule collection for expressing log-based detection methods in vendor-agnostic YAML so they can be shared across teams and security products. This repository contains generic detection, threat-hunting, emerging-threat, compliance, and placeholder rules whose final meaning may be supplied during conversion.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Browse rules organized for several detection goals

The collection includes generic behavioral detections, broader threat-hunting starting points, time-sensitive emerging-threat rules, compliance rules mapped to established frameworks, and placeholders completed during conversion or use.

Sources: [1]

Convert a common rule format for the target platform

Rules are not tied to one vendor query language. Conversion into SIEM-specific queries is handled by separate projects such as Sigma CLI, web converters, or pySigma.

Sources: [1]

Best fit

Share detection knowledge across teams and products

It fits detection engineers and threat hunters who want to maintain log detection methods in a reusable form and evaluate deployment across different SIEM platforms.

Sources: [1]

Before adoption

Validate every rule before production use

This repository is a ruleset, not a runtime that executes detections. Check log-source field mappings, rule status, documented false positives, and generated queries against your telemetry. Repository content uses the Detection Rule License 1.1.

Sources: [1][3]

Official sources

  1. [1]SigmaHQ/sigma README(2026-10-04)
  2. [2]Sigma rules release r2026-07-01(2026-10-04)
  3. [3]Detection Rule License 1.1(2026-10-04)
Supplemental curator note

The rules and the tools that convert them into SIEM queries are separate. Evaluate each rule’s log source, status, and false positives against your own telemetry.

Try it in 3 steps

  1. 1

    Clone the ruleset

    Clone the official repository into an evaluation directory.

    git clone https://github.com/SigmaHQ/sigma.git sigma-rules
  2. 2

    Pin the reviewed revision

    Check out the reviewed commit.

    cd sigma-rules && git checkout ca24243a6e3f94353a54176f83c4c3b7f579224a
  3. 3

    Inspect the included rules

    List YAML rules across the main collections. This does not convert or execute detections in a SIEM.

    find rules rules-threat-hunting rules-emerging-threats rules-compliance rules-placeholder -type f -name '*.yml' | sort | head -20
Check the official README

Growth

Growth trends · Last 30 days

11,152 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
18
Open PRs
232

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • security
  • monitoring
  • siem
  • logging
  • signatures
  • elasticsearch
  • splunk
  • ids
  • sysmon
Stars
11,152
Forks
2,827
Watchers
346
Open issues
6
Contributors
348
Owner type
Organization
Primary language
Python
License
Not determined
Repository last updated
Oct 4, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?