On this page
Overview
Sigma is a specification and rule collection for expressing log-based detection methods in vendor-agnostic YAML so they can be shared across teams and security products. This repository contains generic detection, threat-hunting, emerging-threat, compliance, and placeholder rules whose final meaning may be supplied during conversion.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Browse rules organized for several detection goals
The collection includes generic behavioral detections, broader threat-hunting starting points, time-sensitive emerging-threat rules, compliance rules mapped to established frameworks, and placeholders completed during conversion or use.
Sources: [1]
Convert a common rule format for the target platform
Rules are not tied to one vendor query language. Conversion into SIEM-specific queries is handled by separate projects such as Sigma CLI, web converters, or pySigma.
Sources: [1]
Best fit
Share detection knowledge across teams and products
It fits detection engineers and threat hunters who want to maintain log detection methods in a reusable form and evaluate deployment across different SIEM platforms.
Sources: [1]
Before adoption
Validate every rule before production use
This repository is a ruleset, not a runtime that executes detections. Check log-source field mappings, rule status, documented false positives, and generated queries against your telemetry. Repository content uses the Detection Rule License 1.1.
Official sources
- [1]SigmaHQ/sigma README(2026-10-04)
- [2]Sigma rules release r2026-07-01(2026-10-04)
- [3]Detection Rule License 1.1(2026-10-04)
Supplemental curator note
The rules and the tools that convert them into SIEM queries are separate. Evaluate each rule’s log source, status, and false positives against your own telemetry.
Try it in 3 steps
- 1
Clone the ruleset
Clone the official repository into an evaluation directory.
git clone https://github.com/SigmaHQ/sigma.git sigma-rules - 2
Pin the reviewed revision
Check out the reviewed commit.
cd sigma-rules && git checkout ca24243a6e3f94353a54176f83c4c3b7f579224a - 3
Inspect the included rules
List YAML rules across the main collections. This does not convert or execute detections in a SIEM.
find rules rules-threat-hunting rules-emerging-threats rules-compliance rules-placeholder -type f -name '*.yml' | sort | head -20
Growth
Growth trends · Last 30 days
11,152 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 18
- Open PRs
- 232
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- security
- monitoring
- siem
- logging
- signatures
- elasticsearch
- splunk
- ids
- sysmon
- Stars
- 11,152
- Forks
- 2,827
- Watchers
- 346
- Open issues
- 6
- Contributors
- 348
- Owner type
- Organization
- Primary language
- Python
- License
- Not determined
- Repository last updated
- Oct 4, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Sherlock93,202 Stars
1 shared tag(s) · 1 shared category(s) · Same language
Check username candidates across more than 400 social networks with an OSINT CLI
Python - mitmproxy45,255 Stars
1 shared tag(s) · 1 shared category(s) · Same language
inspect HTTP, HTTP/2, WebSocket, and TLS traffic interactively and transform flows with scripts
Python - JumpServer31,708 Stars
1 shared tag(s) · 1 shared category(s) · Same language
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - Checkov9,054 Stars
1 shared tag(s) · 1 shared category(s) · Same language
statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment
Python - kube-hunter5,087 Stars
1 shared tag(s) · 1 shared category(s) · Same language
probe Kubernetes clusters from outside or inside to expose reachable services and known security weaknesses
Python - mkcert59,718 Stars
1 shared tag(s) · 1 shared category(s)
create a local CA and easily issue browser-trusted TLS certificates for localhost and development domains
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.