One detection idea, written once in YAML, running in ANY SIEM β Splunk, Elastic, Wazuh, Sentinel. Sigma is the universal language of detection engineering.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Rules are readable: where Image endswith mimikatz or command patterns.
Learn 10 modifiers (endswith, contains, reβ¦) and you can read most rules.
PySigma/sigmac compiles YAML β native query languages.
Detection engineering loop in miniature.
Your first authored detection β portfolio-ready immediately.
| logsource | where the log lives |
| detection | fields+conditions |
| contains/endswith | value modifiers |
| condition | combination logic |
| sigmac/uncoder | convert targets |
| falsepositives | declared tuning hints |
uncoder.io converts in-browser when you don't want the CLI.
SOC Prime's public rules + SigmaHQ repo = thousands of examples.
Contribution-friendly repo: get accepted, get real-world credit.
Attack with Atomic Red Team β verify your Sigma fires. That's the craft.
Use Sigma only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.