detection-sigma

Installation
SKILL.md

Sigma Detection Engineering

Overview

Sigma is to log detection what Snort is to network traffic and YARA is to files - a universal signature format for describing security-relevant log events. This skill helps create, validate, and convert Sigma rules for deployment across multiple SIEM platforms, enabling detection-as-code workflows.

Core capabilities:

  • Create detection rules using Sigma format
  • Convert rules to 25+ SIEM/EDR backends (Splunk, Elastic, QRadar, Sentinel, etc.)
  • Validate rule syntax and logic
  • Map detections to MITRE ATT&CK framework
  • Build threat hunting queries
  • Implement compliance-based monitoring

Quick Start

Install Dependencies

Installs
21
GitHub Stars
205
First Seen
May 28, 2026
detection-sigma — agentsecops/secopsagentkit