sigma
Log event descriptor
A standardized format for describing log events to facilitate detection and analysis of security threats
Main Sigma Rule Repository
8k stars
346 watching
2k forks
Language: Python
last commit: 11 months ago
Linked from 7 awesome lists
elasticsearchidsloggingmonitoringsecuritysiemsignaturessplunksysmon
Related projects:
| Repository | Description | Stars |
|---|---|---|
| | A standalone tool for analyzing and detecting security-related events in various Linux logs using SIGMA rules | 684 |
| | A repository for collecting and sharing SIEM rules in STIX format for automated translation to Sigma syntax | 90 |
| | Converts Linux audit logs into standardized JSON format for enhanced security monitoring | 722 |
| | A lightweight React library for drawing network graphs on web pages | 261 |
| | Enables Windows event log settings to support a larger percentage of Sigma detection rules and retain logs for longer periods | 571 |
| | Converts Sigma Rules into STIX 2.1 objects | 7 |
| | A tool for analyzing and visualizing log events using structured rules | 53 |
| | Utilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity. | 1,492 |
| | Provides a searchable, exportable record of read/write events | 365 |
| | A customizable theme for Logseq note-taking software | 51 |
| | Provides daily summaries of frequently reported security advisories from various sources | 249 |
| | Automates analysis of Windows Security Events to identify user logon relations | 241 |
| | Analyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations. | 419 |
| | A toolkit for routing, normalizing, and enriching security event logs across the cloud | 332 |
| | A security-focused application built with Python Django to manage and analyze log data from various sources. | 198 |