Skip to content

thomaspatzke/detection-engineering-with-sigma

Repository files navigation

Workshop: Detection Engineering with Sigma

This workshop introduces Sigma rules and covers the following topics:

  • Introduction to Sigma and the rule format.
  • Value modifiers and conditions.
  • Good practices for writing Sigma rules.
  • Some examples for Sigma rules.
  • Concepts for correlation detections.
  • Some examples for Sigma correlation rules.

The workshop was first presented at Hack.lu 2025 in Luxembourg.

Usage

The PDF contained in this repository contains the slides of the workshop. All rule files are self-contained and can be copy and pasted into sigconverter.io. The file pipeline.yml contains a processing pipeline that is used to show placeholders.

Related Work

Check out the operationalization workshop for learning how Sigma can be integrated into your detection pipeline.

About

Detection Engineering with Sigma workshop (2025)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors