Main Sigma Rule Repository
-
Updated
Oct 2, 2026 - Python
Main Sigma Rule Repository
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
Endpoint detection & Malware analysis software
Consolidation of various resources related to Microsoft Sysmon & sample data/log
ThreatSeeker: Threat Hunting via Windows Event Logs
Open-source MDR home lab — Wazuh, TheHive, Cortex, n8n, pfSense+Suricata. Portfolio project mapped to MITRE ATT&CK
Import and export custom Sysmon configurations using an interactive GUI that lets you build event rules, manage filters, and generate clean XML configs without manually editing Sysmon files.
System Processes Correlation Engine
Malware sandbox for automated PE/ELF analysis with EDR integration and behavioral monitoring. Open-source alternative to CAPE sandbox.
A log-based Threat Hunting tool
Utility to convert SysInternals' Sysmon binary configuration to XML
Browser-based UI for editing, validating, and managing Sysmon XML configs — Flask + vanilla JS, multi-schema support.
This is actually a follow-up to "Mapping-Sysmonlogs-to-ATTACK". After you obtain the "syslog.csv" through program in that repository, you can convert the log into a graph structure with relations through this program
A documented SOC homelab: FortiGate-segmented network, Wazuh SIEM, Suricata NIDS, Sysmon, custom detections mapped to MITRE ATT&CK, and automated response with investigation reports.
Extract logs based off events from sysmon. Comes as a package, cli and ui.
Convert USN Journal Records to Event Logs
Detection engineering lab with Wazuh, Windows/Sysmon, Elastic/KQL rules, ATT&CK mappings, and reproducible validation workflows.
To associate your repository with the sysmon topic, visit your repo's landing page and select "manage topics."