<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>sigma</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/1389/feed"/>
    <updated>2026-06-14T18:02:04+00:00</updated>
    <id>https://links.biapy.com/guest/tags/1389/feed</id>
            <entry>
            <id>https://links.biapy.com/links/12705</id>
            <title type="text"><![CDATA[Rustinel]]></title>
            <link rel="alternate" href="https://karib0u.github.io/rustinel/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12705"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Rustinel is an open-source endpoint detection project for Windows and Linux.

It collects native host telemetry using ETW on Windows and eBPF on Linux, normalizes events into a shared model, evaluates Sigma, YARA, and IOC detections, and writes alerts as ECS NDJSON.

Rustinel is designed for blue teams, detection engineers, researchers, and anyone who wants a transparent endpoint detection engine they can inspect, run, test, and extend.

- [Rustinel @ GitHub](https://github.com/Karib0u/rustinel).]]>
            </summary>
            <updated>2026-05-14T14:18:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10327</id>
            <title type="text"><![CDATA[DetectPack Forge]]></title>
            <link rel="alternate" href="https://detect-pack-forge.vercel.app/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10327"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Turn ideas into detections your SIEM understands. Generate Sigma, KQL, and SPL rules with tests and playbooks in seconds.

 DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk) — plus tests and a response playbook, mapped to MITRE ATT&amp;amp;CK, fully powered by Gen AI. 

- [DetectPack Forge @ GitHub](https://github.com/andrewkolagit/DetectPack-Forge).]]>
            </summary>
            <updated>2025-09-22T05:28:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2107</id>
            <title type="text"><![CDATA[ARM - AttackRuleMap]]></title>
            <link rel="alternate" href="https://attackrulemap.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2107"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Mapping of open-source detection rules and atomic tests. 

The goal of this project is to bridge the gap between Atomic Red Team&amp;#039;s adversary simulations and open-source detection rules. By doing so, this project aims to help security professionals simulate attacks and evaluate their detection strategies more effectively. 🔒

- [AttackRuleMap @ GitHub](https://github.com/krdmnbrk/AttackRuleMap).]]>
            </summary>
            <updated>2025-08-28T21:48:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2618</id>
            <title type="text"><![CDATA[sigconverter.io]]></title>
            <link rel="alternate" href="https://sigconverter.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2618"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[sigma rule converter. An opensource sigma conversion tool built using pysigma.

Welcome to sigconverter.io, a user-friendly converter for Sigma rules. This project is designed to keep in sync with the pySigma project&amp;#039;s backends. Inspired by uncoder.io, it aims to provide an easy-to-use interface for converting Sigma rules.

- [sigconverter.io @ GitHub](https://github.com/magicsword-io/sigconverter.io).]]>
            </summary>
            <updated>2025-08-28T23:13:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3311</id>
            <title type="text"><![CDATA[Hayabusa (隼)]]></title>
            <link rel="alternate" href="https://github.com/Yamato-Security/hayabusa" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3311"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.]]>
            </summary>
            <updated>2025-08-29T01:08:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4321</id>
            <title type="text"><![CDATA[Zircolite]]></title>
            <link rel="alternate" href="https://github.com/wagga40/Zircolite" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4321"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs.

- [Comment effectuer une investigation numérique sur les journaux d’évènements Windows avec Zircolite ? @ IT-Connect :fr:](https://www.it-connect.fr/zircolite-investigation-numerique-journaux-securite-windows/).]]>
            </summary>
            <updated>2025-08-29T03:58:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4626</id>
            <title type="text"><![CDATA[Sigma]]></title>
            <link rel="alternate" href="https://sigmahq.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4626"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SIEM Detection Format. The shareable detection format for security professionals.

Sigma is a generic, open, and structured detection format that allows security teams to detect relevant log events in a simple and shareable way. 

Detection engineers, threat hunters and all defensive security practitioners collaborate on detection rules. The repository offers more than 3000 detection rules of different type and aims to make reliable detections accessible to all at no cost.

- [Sigma @ GitHub](https://github.com/SigmaHQ/sigma).
- [C&amp;#039;est la fin des antivirus @ Underscore_&amp;#039;s Spotify :fr:](https://open.spotify.com/episode/027iVKcWMdQOmA4iBMduJL).
- [🚨 Découvrez Sigma: l&amp;#039;outil open-source qui révolutionne la détection de menaces ! 🚨 @ Maory SChroder&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/maory-schroder_cybersaezcuritaez-siem-threathunting-activity-7230094685615067136-Y5wi).]]>
            </summary>
            <updated>2025-08-29T04:47:46+00:00</updated>
        </entry>
    </feed>
