Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

Sigma

Generic signature format for SIEM/detection rules convertible to Splunk, Elastic, KQL, and many backends.

Why it is included

Open lingua franca for sharing detection logic across vendors.

Best for

Detection engineers publishing portable rules and CI validation.

Strengths

  • Converter ecosystem
  • Community rule repo
  • CI tooling

Limitations

  • Backend mapping quirks require testing

Good alternatives

Splunk SPL only · YARA (different layer)

Related tools