Skip to content
Security
Skill

/detection-sigma

Generic detection rule creation and management using Sigma, the universal SIEM rule format. Sigma provides vendor-agnostic detection logic for log analysis across multiple SIEM platforms. Use when: (1) Creating detection rules for security monitoring, (2) Converting rules

From plugin
secopsagentkit
18331 skills
Install
$ npx -y skills add AgentSecOps/SecOpsAgentKit --skill detection-sigma --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/detection-sigma

Context preview

The summary Claude sees to decide when to auto-load this skill.

Generic detection rule creation and management using Sigma, the universal SIEM rule format. Sigma provides vendor-agnostic detection logic for log analysis across multiple SIEM platforms. Use when: (1) Creating detection rules for security monitoring, (2) Converting rules

SKILL.md

detection-sigma.SKILL.md
name: detection-sigma
description: >
  Generic detection rule creation and management using Sigma, the universal SIEM rule format.
  Sigma provides vendor-agnostic detection logic for log analysis across multiple SIEM platforms.
  Use when: (1) Creating detection rules for security monitoring, (2) Converting rules between
  SIEM platforms (Splunk, Elastic, QRadar, Sentinel), (3) Threat hunting with standardized
  detection patterns, (4) Building detection-as-code pipelines, (5) Mapping detections to
  MITRE ATT&CK tactics, (6) Implementing compliance-based monitoring rules.
version: 0.1.0
maintainer: SirAppSec
category: incident-response
tags: [sigma, detection, siem, threat-hunting, mitre-attack, detection-engineering, log-analysis]
frameworks: [MITRE-ATT&CK, NIST, ISO27001]
dependencies:
  python: ">=3.8"
  packages: [pysigma, pysigma-backend-splunk, pysigma-backend-elasticsearch, pyyaml]
references:
  - https://github.com/SigmaHQ/sigma
  - https://github.com/SigmaHQ/pySigma
  - https://sigmahq.io/

Sigma Detection Engineering

Overview

Sigma is to log detection what Snort is to network traffic and YARA is to files - a universal signature format for describing security-relevant log events. This skill helps create, validate, and convert Sigma rules for deployment across multiple SIEM platforms, enabling detection-as-code workflows.

**Core capabilities**:

  • Create detection rules using Sigma format
  • Convert rules to 25+ SIEM/EDR backends (Splunk, Elastic, QRadar, Sentinel, etc.)
  • Validate rule syntax and logic
  • Map detections to MITRE ATT&CK framework
  • Build threat hunting queries
  • Implement compliance-based monitoring

Quick Start

Install Dependencies

pip install pysigma pysigma-backend-splunk pysigma-backend-elasticsearch pyyaml

Create a Basic Sigma Rule

title: Suspicious PowerShell Execution
id: 7d6d30b8-5b91-4b90-a71e-4f5a3f5a3c3f
status: experimental
description: Detects suspicious PowerShell execution with encoded commands
references:
    - https://attack.mitre.org/techniques/T1059/001/
author: Your Name
date: YYYY/MM/DD
modified: YYYY/MM/DD
tags:
    - attack.execution
    - attack.t1059.001
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith: '\powershell.exe'
        CommandLine|contains:
            - '-enc'
            - '-EncodedCommand'
            - 'FromBase64String'
    condition: selection
falsepositives:
    - Legitimate administrative scripts
level: medium

Convert Rule to Target SIEM

# Convert to Splunk
python scripts/sigma_convert.py rule.yml --backend splunk

# Convert to Elasticsearch
python scripts/sigma_convert.py rule.yml --backend elasticsearch

# Convert to Microsoft Sentinel
python scripts/sigma_convert.py rule.yml --backend sentinel

Core Workflows

Workflow 1: Detection Rule Development

Progress: [ ] 1. Identify detection requirement from threat intelligence or compliance [ ] 2. Research log sources and field mappings for target environment [ ] 3. Create Sigma rule using standard template [ ] 4. Validate rule syntax: `python scripts/sigma_validate.py rule.yml` [ ] 5. Test rule against sample logs or historical data [ ] 6. Convert to target SIEM format [ ] 7. Deploy and tune based on false positive rate [ ] 8. Document rule metadata and MITRE ATT&CK mapping

Work through each step systematically. Check off completed items.

Workflow 2: Threat Hunting Rule Creation

For proactive threat hunting based on TTPs:

1. **Select MITRE ATT&CK Technique**

  • Review threat intelligence for relevant TTPs
  • Identify technique ID (e.g., T1059.001 - PowerShell)
  • See [references/mitre-attack-mapping.md](references/mitre-attack-mapping.md) for common techniques

2. **Identify Log Sources**

  • Determine which logs capture the technique
  • Map log source categories (process_creation, network_connection, file_event)
  • Verify log source availability in your environment

3. **Define Detection Logic**

  • Create selection criteria matching suspicious patterns
  • Add filters to reduce false positives
  • Use field modifiers for robust matching (endswith, contains, re)

4. **Validate and Test**

  • Run validation: `python scripts/sigma_validate.py hunting-rule.yml`
  • Test against known-good and known-bad samples
  • Tune detection logic based on results

5. **Document and Deploy**

  • Add references to threat reports
  • Document false positive scenarios
  • Convert and deploy to production SIEM

Workflow 3: Bulk Rule Conversion

When migrating between SIEM platforms:

# Validate all rules first
python scripts/sigma_validate.py --directory rules/ --report validation-report.json

# Convert entire rule set
python scripts/sigma_convert.py --directory rules/ --backend splunk --output converted/

# Generate deployment report
python scripts/sigma_convert.py --directory rules/ --backend splunk --report conversion-report.md

Review conversion report for:

  • Successfully converted rules
  • Rules requiring manual adjustment
  • Unsupported field mappings
  • Backend-specific limitations

Workflow 4: Compliance-Based Detection

For implementing compliance monitoring (PCI-DSS, NIST, ISO 27001):

1. **Map Requirements to Detections**

  • Identify compliance control requirements
  • Determine required log monitoring
  • See [references/compliance-mappings.md](references/compliance-mappings.md)

2. **Create Detection Rules**

  • Use compliance rule templates from `assets/compliance-rules/`
  • Tag rules with compliance framework (e.g., tags: [pci-dss.10.2.5])
  • Set appropriate severity levels

3. **Validate Coverage**

  • Run: `python scripts/compliance_coverage.py --framework pci-dss`
  • Review coverage gaps
  • Create additional rules as needed

4. **Generate Compliance Report**

  • Document detection coverage by control
  • Include sample queries and expected alerts
  • Maintain audit trail fo
Read more
Ships withsecopsagentkit

An assortment of security operations skills for AI coding agents. A collaborative approach to shift-left security using Claude Code skills.

Get the whole plugin
Stats
184
Stars
35
Forks
Maintained
Maintenance
Python
Language
3mo ago
Last commit
8mo ago
Created

Repo: AgentSecOps/SecOpsAgentKit

Other skills on secopsagentkit.