Ross ROSS = Recommend OSS · open-source software intelligence for agents

SigmaHQ/sigma resource

Main Sigma Rule Repository observed · 2026-08-28

github.com/SigmaHQ/sigma · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

92/100

  • Activity 98
  • Release rhythm 80
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 53.5
  • age_days: 3539
  • days_rel: 55
  • days_push: 15
  • n_releases_24m: 11

Full methodology

Adoption not part of the score

10943 stars · 2769 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

The main SigmaHQ repository containing over 3000 community-maintained Sigma detection rules written in a generic YAML format for describing malicious log events. Rules convert into queries for SIEM platforms like Splunk, Elasticsearch, Microsoft Sentinel, and QRadar via the sigma-cli tool and pySigma backends.

Use cases

  • detect malicious activity in SIEM logs
  • convert detection rules to Splunk or Elasticsearch queries
  • threat hunt for suspicious behavior in log data
  • share portable vendor-neutral detection rules
  • find rules for specific APT campaigns or zero-day exploits
  • check compliance violations against CIS or NIST frameworks

When to choose

  • you run a SIEM and want free, community-maintained detection content
  • you need vendor-neutral detection rules portable across Splunk, Sentinel, Elastic, and others
  • you are a threat hunter or detection engineer looking for a starting rule base

When to avoid

  • you need network traffic or file signatures (use Snort or YARA instead)
  • you want a turnkey monitoring product rather than rule content
  • you need rules for a SIEM with no available pySigma backend

Facets

dataset · maturity active

security monitoring logging search-engine security monitoring developer-tools cross-platform python cli siem detection-rules threat-hunting yara-for-logs splunk elasticsearch sysmon soc yaml-rules detection-engineering

7 sources

Member repositories

RepositoryRoleHealth v2
SigmaHQ/sigmamain92

For agents

markdown · JSON · MCP: product_card(name="SigmaHQ/sigma")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem