This workshop introduces Sigma rules and covers the following topics:
- Introduction to Sigma and the rule format.
- Value modifiers and conditions.
- Good practices for writing Sigma rules.
- Some examples for Sigma rules.
- Concepts for correlation detections.
- Some examples for Sigma correlation rules.
The workshop was first presented at Hack.lu 2025 in Luxembourg.
The PDF contained in this repository contains the slides of the workshop. All
rule files are self-contained and can be copy and pasted into
sigconverter.io. The file pipeline.yml contains a
processing pipeline that is used to show placeholders.
Check out the operationalization workshop for learning how Sigma can be integrated into your detection pipeline.