Sigma
Sigma is a generic and open signature format for SIEM systems. It allows you to describe relevant log events straightforwardly. The rule format is very flexible, easy to write, and applicable to any log file type. This project’s primary purpose is to provide a structured form in which researchers or analysts can describe their once developed detection methods and make them shareable with others. Sigma means to be an open standard in which such detection mechanisms can be defined, shared, and collected to improve everyone’s detection capabilities.
Specialties
Integrations
Built By ThreatConnect