SigmaHQ/sigma resource
Main Sigma Rule Repository observed · 2026-08-28
Health v2 · maintenance only
92/100
- Activity 98
- Release rhythm 80
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 53.5
- age_days: 3539
- days_rel: 55
- days_push: 15
- n_releases_24m: 11
Adoption not part of the score
10943 stars · 2769 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
The main SigmaHQ repository containing over 3000 community-maintained Sigma detection rules written in a generic YAML format for describing malicious log events. Rules convert into queries for SIEM platforms like Splunk, Elasticsearch, Microsoft Sentinel, and QRadar via the sigma-cli tool and pySigma backends.
Use cases
- detect malicious activity in SIEM logs
- convert detection rules to Splunk or Elasticsearch queries
- threat hunt for suspicious behavior in log data
- share portable vendor-neutral detection rules
- find rules for specific APT campaigns or zero-day exploits
- check compliance violations against CIS or NIST frameworks
When to choose
- you run a SIEM and want free, community-maintained detection content
- you need vendor-neutral detection rules portable across Splunk, Sentinel, Elastic, and others
- you are a threat hunter or detection engineer looking for a starting rule base
When to avoid
- you need network traffic or file signatures (use Snort or YARA instead)
- you want a turnkey monitoring product rather than rule content
- you need rules for a SIEM with no available pySigma backend
Facets
dataset · maturity active
security monitoring logging search-engine security monitoring developer-tools cross-platform python cli siem detection-rules threat-hunting yara-for-logs splunk elasticsearch sysmon soc yaml-rules detection-engineering
7 sources
- readme: https://github.com/SigmaHQ/sigma · fetched 2026-08-28 · abae5de40674
- homepage: https://sigmahq.io/ · fetched 2026-08-29 · 0e3bdab78e0d
- site_page: https://sigmahq.io/docs/guide/getting-started.html · fetched 2026-08-29 · 7d27129b64a0
- site_page: https://sigmahq.io/docs/digging-deeper/backends · fetched 2026-08-29 · 912b8f202da1
- site_page: https://sigmahq.io/docs/guide/about · fetched 2026-08-29 · bf5def67e42f
- site_page: https://sigmahq.io/docs/basics/rules.html · fetched 2026-08-29 · 54dc56960073
- site_page: https://sigmahq.io/docs/guide/about.html · fetched 2026-08-29 · bf5def67e42f
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| SigmaHQ/sigma | main | 92 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem