Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 1158

Sigma Rule

Reviewed byCybersecurity entrepreneur & security researcher

What is Sigma Rule?

Sigma RuleA vendor-neutral, YAML-based detection signature for log events that can be converted into queries for SIEM, EDR, or XDR back-ends.


Sigma is an open detection-engineering format created by Florian Roth and Thomas Patzke that lets analysts describe a log-based detection once and translate it into many query dialects — Splunk SPL, Elastic ES|QL, Microsoft Sentinel KQL, Google Chronicle YARA-L, and more. It plays the role for generic log events that YARA plays for files and Snort/Suricata play for network traffic: a portable, shareable lingua franca so a detection published by one team runs on another's stack.

A rule is YAML with three key parts: metadata (a UUID id, a level from informational to critical, and tags mapping to MITRE ATT&CK techniques), a logsource (product, service, or category such as process_creation), and a detection block of named selectors combined by a condition expression. Field values support modifiers like contains, startswith, and re for regex.

Conversion moved from the legacy sigmac tool to the modular pySigma library and its sigma CLI, which apply per-backend pipelines that remap field names to each product's schema. The SigmaHQ GitHub repository curates thousands of community rules covering Windows Event Logs, Sysmon, Linux auditd, AWS CloudTrail, Okta, and Kubernetes. Sigma also added correlation rules for counting, thresholds, and temporal sequences across events.

flowchart LR
  A[Analyst writes Sigma rule in YAML] --> B[logsource + detection + condition]
  B --> C[pySigma converter + backend pipeline]
  C --> D1[Splunk SPL]
  C --> D2[Sentinel KQL]
  C --> D3[Elastic ES-QL]
  C --> D4[Chronicle YARA-L]
  D1 --> E[Deployed as SIEM/EDR detection]
  D2 --> E
  D3 --> E
  D4 --> E
  E --> F[Alert on matching log events]

● Examples

  1. 01

    A Sigma rule detecting suspicious child processes of winword.exe to flag macro-driven malware.

  2. 02

    Converting a Sigma rule with pySigma into Microsoft Sentinel KQL for an analytics rule deployment.

● Frequently asked questions

What is Sigma Rule?

A vendor-neutral, YAML-based detection signature for log events that can be converted into queries for SIEM, EDR, or XDR back-ends. It belongs to the Defense & Operations category of cybersecurity.

What does Sigma Rule mean?

A vendor-neutral, YAML-based detection signature for log events that can be converted into queries for SIEM, EDR, or XDR back-ends.

How do you defend against Sigma Rule?

Defences for Sigma Rule typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for Sigma Rule?

Common alternative names include: Sigma signature, Sigma format.

● Related terms

● See also