Filter
Exclude
Time range
-
Near
2 Dec 2025
๐Ÿšจ๐—•๐—ถ๐—ด ๐—ฑ๐—ฎ๐˜† ๐—ณ๐—ผ๐—ฟ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป๐—ฆ๐˜๐—ฟ๐—ฒ๐—ฎ๐—บ. ๐—ข๐—ป๐—ฒ ๐—ผ๐—ณ ๐—ผ๐˜‚๐—ฟ ๐—น๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜€๐˜ ๐—ฟ๐—ฒ๐—น๐—ฒ๐—ฎ๐˜€๐—ฒ๐˜€ ๐˜†๐—ฒ๐˜. The platform now supports official pySigma validation fully in-browser, compiled to WebAssembly. Same validation as sigma-cli. Thanks to @sifex from detection.studio for the inspiration behind the implementation. Hereโ€™s what we added: โ€ข ๐—ฆ๐—บ๐—ฎ๐—ฟ๐˜ ๐—ณ๐—ถ๐—ฒ๐—น๐—ฑ ๐˜ƒ๐—ฎ๐—น๐—ถ๐—ฑ๐—ฎ๐˜๐—ถ๐—ผ๐—ป: Auto-suggests correct field names and catches typos before they become a problem. โ€ข ๐—˜๐—ฎ๐—ฟ๐—น๐˜† ๐—ฟ๐˜‚๐—น๐—ฒ ๐˜ƒ๐—ฎ๐—น๐—ถ๐—ฑ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐—ป ๐˜๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด ๐—ฐ๐—ต๐—ฎ๐—น๐—น๐—ฒ๐—ป๐—ด๐—ฒ๐˜€: Invalid rules get blocked before evaluation, making the workflow smoother. โ€ข ๐Ÿญ๐Ÿฏ ๐—ป๐—ฒ๐˜„ ๐—ฐ๐—ต๐—ฎ๐—น๐—น๐—ฒ๐—ป๐—ด๐—ฒ๐˜€:ย x10 new Sigma and x3 new Suricata challenges โ€ข ๐—˜๐—ฉ๐—ง๐—ซ ๐—ฝ๐—ฎ๐—ฟ๐˜€๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—ฏ๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ:ย Powered by WebAssembly and based on LUMEN[1] by @KoifSec, letting you load and analyze .evtx files locally. โ€ข ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฆ๐—ถ๐—ด๐—บ๐—ฎ ๐—ฟ๐˜‚๐—น๐—ฒ๐˜€:ย Synced with the latest upstream repository release. โ€ข ๐—ฆ๐—บ๐—ฎ๐—ฟ๐˜๐—ฒ๐—ฟ ๐˜ƒ๐—ฎ๐—น๐—ถ๐—ฑ๐—ฎ๐˜๐—ถ๐—ผ๐—ป:ย Placeholder detection, logsource taxonomy checks, and clearer error messages. โ€ข ๐—ฃ๐—ฒ๐—ฟ๐—ณ๐—ผ๐—ฟ๐—บ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐˜€๐˜๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† ๐—ถ๐—บ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜๐˜€:ย Faster, more consistent behavior across the whole platform. EVERYTHING is FREE, but donโ€™t confuse free with low quality. A big step forward. Next up, our training module... Full changelog here: detectionstream.com/changeloโ€ฆ [1]:ย lumen.koifsec.me
1
10
39
3,120
20 Oct 2025
logSourceใŒ็ต‚ๅฃฒใซใชใ‚‹ใจ่žใ„ใŸใฎใงใพใ ๅฐ‘ใ—ๆฎ‹ใฃใฆใ‚‹ใŒ4ๆœฌใ‚‚่ฒทใฃใฆใ—ใพใฃใŸ๐Ÿ˜ ใ™ใ”ใๆฎ‹ๅฟต #Zenko #logSource #ใƒญใ‚ฐใ‚ฝใƒผใ‚น
3
199
้ฃฝใใŸ๏ผๅ‘ณๅค‰ใซใƒญใ‚ฐใ‚ฝใƒผใ‚นๆŠ•ๅ…ฅ๏ผ๏ผ ใ‚ใฃใกใ‚ƒ็พŽๅ‘ณใ—ใ„๏ผ๏ผ๏ผ็ฌ‘ #LOGsource
15
1,966
Weโ€™ve published a deep dive into how Aurora uses ETW to reconstruct structured event data for detection engineering The post covers: - ETW-based logsource mappings - Custom field enrichment (e.g., ProcessTree, GrandparentCommandLine) - Gaps in ETW coverage and where minimal Sysmon configs help - Practical detection use cases with full Sigma rules - Techniques for exploring ETW with --trace and writing custom rules ๐Ÿ”— nextron-systems.com/2025/07/โ€ฆ by @_swachchhanda_ #Sigma #AuroraAgent #ETW #DetectionEngineering
1
11
42
15,762
Replying to @marunakahonten2
LOGSAUCE๏ผŸ็ตๅฑ€ไฝ•ใชใ‚“๏ผŸ๐Ÿค”๐Ÿ’ฆใฃใฆๅˆ่ฆ‹ใฎๆ–นใงๆ€ใฃใฆใ‚‹ไบบใ‚‚ๅฐ‘ใชใ‹ใ‚‰ใšๅฑ…ใ‚‰ใ‚Œใ‚‹ใจๆ€ใ„ใพใ™ใฎใงใถใฃใกใ‚ƒใ‘ใ‚‹ใจๅŸบๆœฌBBQใ‚ฝใƒผใ‚นใงใ™๐Ÿ˜…ใ€€ใงใ‚‚่‰ฒใ‚“ใชๆ–™็†ใฎ้š ใ—ๅ‘ณใซใ‚‚ใชใฃใŸใ‚Š้คƒๅญใ‚„ใƒใƒณใƒใƒผใ‚ฐใซใ‹ใ‘ใฆใ‚‚็พŽๅ‘ณใ—ใ„ใงใ™ใ‚ˆใƒผ๐Ÿ˜†ใ€€#LOGSOURCEใ€€#ใƒญใ‚ฐใ‚ฝใƒผใ‚นใ€€#่พปๅ–„ๅ…‰
2
59
Replying to @beer_nomu_nomu
ใพใ•ใซใ“ใฎ็Šถๆณใ‚’ไฝ“้จ“โ€ฆใ€‚ใ—ใ‹ใ‚‚ไธปๆ‹…ๅฝ“ใ€‚ใพใšSIEMใฃใฆไฝ•๏ผŸใ‹ใ‚‰ๅง‹ใพใ‚Šใ€SOCใƒ™ใƒณใƒ€ใƒผใซๆง‹็ฏ‰ใ‚’ไพ้ ผใ™ใ‚‹ใ‚‚ใ€ใชใ‚“ใ ใ‹ใ‚“ใ ใง็›ดใใซ็€ๆ‰‹ใงใใšโ€ฆใงใ‚‚ใ€ๆœŸ้™ใฏๅˆ‡ใ‚‰ใ‚Œใฆใ‚‹ใ€‚ใƒžใƒ‹ใƒฅใ‚ขใƒซ็‰‡ๆ‰‹ใซ็’ฐๅขƒๆง‹็ฏ‰ใ€LogSource้€ฃๆบใ€ๆ›ดใซไธฆ่กŒใ—ใฆใ‚คใƒณใ‚ทใƒ‡ใƒณใƒˆใƒ•ใƒญใƒผไฝœๆˆใ€ไฝ“ๅˆถๆง‹็ฏ‰โ€ฆใใ—ใฆ้‹็”จโ€ฆใ‚„ใ‚ŠใใฃใŸ่‡ชๅˆ†ใ‚’่ค’ใ‚ใŸใ„๐Ÿ’ฆ
1
1
76
Do #SPCSS hledรกme IT detektiva ๐Ÿ”Ž Vรญ, o ฤem je: ๐Ÿ’ป #CyberSecurity ๐Ÿ’ป IT infrastruktura ๐Ÿ’ป logsource management, pentesty, konfigurace, dtb, hardening, attack surface mngm,โ€ฆ ale hlavnฤ› SPRรVA ZRANITELNOSTร. Prestiลพnรญ prรกce i firma, fajn tรฝm, vรฝhody atd.โญ 1url.cz/M1Nof
2
81
26 Apr 2024
sigma logsource-guides Eventlog This logsource guide describes how to enable the necessary logging to make use of SIGMA rules that leverage the security service. github.com/SigmaHQ/sigma/bloโ€ฆ

2
427
14 Mar 2024

1
2
392
๐Ÿช„New #SigmaHQ r2024-03-11 release is here. ๐ŸŒŸ28 New Rules ๐Ÿ›ก๏ธ5 Rule updates ๐Ÿ”ฌ 5 Rule Fixes Here is a snippet from this release - New rules detecting GitHub "Secret Scanning" or "Push Protection" feature disabling. - New logsource and set of rules leveraging OpenCanary logs. - Increased coverage for a couple of old DLL loading rules. - Tuning for DLL sideloading based rules. And much more ๐Ÿš€ You can read about this by checking the release highlight blog -> blog.sigmahq.io/sigmahq-ruleโ€ฆ Or check the full change log and start exploring this, by downloading the latest release -> github.com/SigmaHQ/sigma/relโ€ฆ A special thanks to the many contributors that helped shape this release, specifically @benmontour @CrimpSec @DefensiveDepth @faisalusuf @frack113 @qasimqlf @AltgeltMax, snajafov, swachchhanda000, tr0mb1r, @X__Junior
20
55
16,939
Come join us this Friday to talk about how to process a report and extract detection and look for detection opportunities and ideas. One of the things that i'm fascinated by when looking at a threat report is your perspective will change depending on your level involvement in the detection pipeline. Are you only covering the procedure? Or do you care about different implementation? do you have time to study the technique and find better indicators? What about the logsource does this technique emits a process creation / file event / dns ? All interesting questions. That i'll try to discuss this Friday๐Ÿ˜
โš›๏ธPurple March Madness๐Ÿ’œ continues! If you havenโ€™t yet, catch up on our latest episode ๐Ÿ”„. Then, mark your calendars ๐Ÿ—“๏ธ for March 8 with @nas_bench as we embark on The Detection Journey ๐Ÿ”. Dive deeper into cybersecurity with us! - youtube.com/watch?v=vF7j2G2oโ€ฆ
2
4
19
3,903
1 Mar 2024
only Detection Engineers really know what logsource means
2
11
1,060
With the Aurora agent (nextron-systems.com/aurora/) we subscribe by default to this provider. Which means you can write sigma rules using the following logsource product: windows service: amsi You'll have access to all fields such as Content, Appname, ScanResult... And the matches are outputted in the event logs.
Did you know that when you disable "Real-time protection" on defender, its true that you won't receive events on the Defender Event log anymore (related to that feature). But if you actually subscribe to the AMSI ETW {2A576B87-09A7-520E-C21A-4942F0271D67} provider you'd still receive AMSI events. Example below from Powershell process. Time to leverage that detection source if you haven't already :)
1
9
33
21,551
Starting today, if you know one of the SIEM, EDR or Data Lake languages, you know them all! Dear industry, please meet RootA roota.io RootA is a public-domain language for collective cyber defense, created to make threat detection, incident response, and actor attribution simple. It acts as an open-source wrapper on top of most of the existing SIEM, EDR, XDR, and Data Lake query languages. If you learn the basics of RootA, you will be able to contribute to collective defense. And if you have mastered a specific SIEM language, with RootA and Uncoder.IO you can speak them all. Inspired by success of Yara and Sigma rules, RootA is focused on a broader applicability by a larger community of defenders. RootA is expressed using YAML, a wide-spread, easy-to-write and human-readable format. Use any query language for detection, Uncoder.IO will take care of the translation. Correlation support. Common correlations are supported by RootA in order to make detection logic harder to bypass by the attackers, more compute efficient and future proof. Log sources can be explicitly or implicitly defined in the native query itself or in the customizable logsource field. RootA syntax fully accommodates #OCSF and #Sigma providing maximum compatibility for Detection Engineers. Threat Actor Timeline. While Actors change, behaviours often stay the same. RootA supports an additional threat intelligence layer for CERTs, NCSCs, ISACs, MDRs, and Defence Agencies, to coordinate defence faster and with greater precision. Mapping to TTPs. Link detection logic to related tactics, techniques, and procedures in terms of MITRE ATT&CKยฎ. You can start writing RootA rules in any code editor that supports YAML. To translate RootA rules to other languages use Uncoder.IO by building it from source github.com/UncoderIO/Uncoderโ€ฆ or hosted online privately by SOC Prime since 2018 at uncoder.io I am beyond grateful to everybody on SOC Prime team, our customers, friends, families and Sigma community for your ongoing support, belief, inspiration and feedback. Special gratitude to Alex Bredikhin Ruslan Mikhalov Adam Swan and Roman Ranskyi for working on the language specification and designs together. Nothing is impossible! Source github.com/UncoderIO/RootA
3
104
356
61,635
.@m3nixx and I took some time this weekend to cook something cool for Sigconverter sigconverter.io ๐Ÿง‘โ€๐Ÿณ You can now apply custom pySigma processing pipelines directly on the website. You might ask what does this mean? Custom processing pipelines allows you to transform a SIGMA rule before it is converted to the target backend. ๐Ÿง™โ€โ™‚๏ธ These transformation might include Field Mapping, LogSource Change, Replace Strings....etc. ๐Ÿš€ These would allow you to customize the Sigma rule output exactly to your environment needs. You can read more about these pipelines and how to leverage them in this @sigma_hq blog -> blog.sigmahq.io/connecting-sโ€ฆ The best thing about this is that with the recently announced sharing feature. You can now create a bookmark with an already saved pipeline and every time you want to convert a rule it'll be applied ๐Ÿ”ฅ We'll also be enabling the post processing templating feature in the coming days for a more customizable output. Stay tuned ๐Ÿ•‘
3
24
66
21,141
A nice blog post from Jonny & Carlos ๐Ÿ’™ Wanted to add that the Aurora agent captures by default the Microsoft-Windows-LDAP-Client ETW logs. You can write Sigma rules using the logsource product: windows service: ldap All events are exposed. So you can specify EventID: 30 for example to capture some of the search filters mentioned in the blog and get alerts in the event log or you can forward them to your Siem for more correlation :)
Happy Monday! Today @Carlos_Perez and I are releasing a blog on adversarial LDAP tradecraft. In this write-up we show: - Normal LDAP queries you might see - Common LDAP queries adversaries and red teams use - Telemetry you can use to see these LDAP queries - A way to get around the logging Check it out: binarydefense.com/resources/โ€ฆ
2
5
43
37,758
17 Aug 2023
I've done a little housekeeping in the @sigma_hq rules for the ๐™ง๐™š๐™œ๐™ž๐™จ๐™ฉ๐™ง๐™ฎ_๐™จ๐™š๐™ฉ logsource. You don't need to put `EventType: SetValue` and even less `EventID: 13` in your detection part. Check : github.com/SigmaHQ/sigma-speโ€ฆ Don't hesitate to contribute, bring up the FPs ๐Ÿ˜€

1
4
197
4 May 2023
I have add a little GUI POC for my github.com/frack113/sigma_loโ€ฆ. It is my first python QT ,don't hope to much ๐Ÿ˜… But you can see how to select @sigma_hq rules by logsource with simple questions.
1
3
224
Thanks to DustInDark and Fukusuke Takahashi, the latest Hayabusa v2.3.1 now supports all used pipe keywords and condition statements. The last thing is to support the logsource keywords and then it will completely natively support sigma rules. (No conversion necessary!)
1
8
1,085
Logsource and Detection guides as well as detection validation, rule releases, and much more are all coming to SIGMA in the next couple of months. It's gonna be good ๐Ÿ”ฅ
1
10
53
9,045