All tools

Defensive / Blue

Sigma Rules

Generic detection rule format convertible to SIEM queries.

intermediate
Any
Defense

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Writing detections for techniques you just learned to attack.

How

Author Sigma; convert with sigma-cli to Splunk/Elastic/etc.

Why

Red teamers who understand detection become elite operators.

Commands & usage

sigma convert -t splunk rule.yml

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

detection
siem
purple

Related in Defensive / Blue