home/toolvault/soc & defense/sigma

Sigma //

SOC & Defensedetection rules

One detection idea, written once in YAML, running in ANY SIEM β€” Splunk, Elastic, Wazuh, Sentinel. Sigma is the universal language of detection engineering.

difficulty Β· intermediate
20 min
time to first win
5
guided steps
0
students started here*

HOW TO USE SIGMA

Follow the steps β€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

sigma β€” guided lab session
static view
step 01

Read a real rule

sigma/rules/windows/process_creation/proc_creation_win_mimikatz.yml

Rules are readable: where Image endswith mimikatz or command patterns.

step 02

Anatomy check

title / logsource / detection / condition

Learn 10 modifiers (endswith, contains, re…) and you can read most rules.

step 03

Convert to your SIEM

sigmac -t splunk rule.yml

PySigma/sigmac compiles YAML β†’ native query languages.

step 04

Test against your lab

run the attack β†’ rule fires in dashboard

Detection engineering loop in miniature.

step 05

Write your own

rule: powershell -enc detection

Your first authored detection β€” portfolio-ready immediately.

THE WORKFLOW AT A GLANCE

πŸ“–
Read
SigmaHQ rules
🧠
Logic
fields+condition
πŸ”
Compile
to your SIEM
πŸ§ͺ
Test
attack the lab
✍️
Author
your rules
LEARNING CURVE
intermediate β€” 20 min to first win

FLAGS & SUPER-MOVES

logsourcewhere the log lives
detectionfields+conditions
contains/endswithvalue modifiers
conditioncombination logic
sigmac/uncoderconvert targets
falsepositivesdeclared tuning hints

PRO TIPS

01

uncoder.io converts in-browser when you don't want the CLI.

uncoder.io converts in-browser when you don't want the CLI.

02

SOC Prime's public rules + SigmaHQ repo = thousands of examples.

SOC Prime's public rules + SigmaHQ repo = thousands of examples.

03

Contribution-friendly repo

Contribution-friendly repo: get accepted, get real-world credit.

04

Attack with Atomic Red Team β†’ verify your Sigma fires. That's the craft.

Attack with Atomic Red Team β†’ verify your Sigma fires. That's the craft.

βš–οΈ

Golden rule

Use Sigma only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 Β· v2 immersive Β· latest news
Made for learners, everywhere Β· 2026
*plausibly. verify commands with official docs.