sigma-specification

Sigma Specification - Generic Signature Format for SIEM Systems


Sigma Logo

</a>

Sigma Official Badge GitHub Repo stars
Open Source Security Index - Fastest Growing Open Source Security Projects

Welcome to the official Sigma Specification repository.

A Quick Rundown

Here’s what you can expect from each of the main subfolders within this repo. Please take a minute to educate yourself!

Specification

Specification will contain markdown files describing the Sigma specification format in details. The appendix files provide more detailed information on certain aspects to facilitate reading and research.

JSON Schema

Json-Schema will contain a list of JSON schemas for the following.

SigmaHQ

SigmaHQ will contain markdown files that describe rules and recommendations that are applied to the rules hosted in SigmaHQ main rule repository.

[!NOTE] The SigmaHQ folder and the files contains within are not part of the sigma specification. They are there to ensure and easier management of the rules hosted in the main rule repository

Version Changes

You can read more on the potential breaking changes and additional features introduced in version:

Other folder

The other directories are only there for operational purposes.