The Lab · Detection

Sigma lab

Sigma is an open, vendor-neutral rule format from the SigmaHQ community: you write a detection once as a small YAML file, and a converter turns it into your SIEM's query language. Six exhibits cover writing a rule, its modifiers, tuning, log sources, ATT&CK coverage and counting over time.

Everything runs in this tab on seeded synthetic logs: fictional hosts, .test domains, documentation address blocks and inert strings. The rule language is a labelled subset of Sigma, the two query styles are illustrative, and only your progress is saved. MITRE ATT&CK® is a registered trademark of The MITRE Corporation, and technique IDs and names are used under MITRE's terms of use.