SIGMA RULES
Sigma is a generic signature format for SIEM systems. Write once, convert to Splunk, Elastic, QRadar, etc.
INSTALLATION#
pip install sigma-cli pip install pySigma # With backends pip install pySigma-backend-splunk pip install pySigma-backend-elasticsearch
RULE STRUCTURE#
BASIC TEMPLATE#
title: Rule Title
id: UUID-here
status: experimental
description: Description of what the rule detects
author: Your Name
date: 2024/01/01
modified: 2024/01/15
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains: '-enc'
condition: selection
falsepositives:
- Administrative scripts
level: high
tags:
- attack.execution
- attack.t1059.001
REQUIRED FIELDS#
title Rule name logsource Log source definition detection Detection logic
OPTIONAL FIELDS#
id Unique identifier (UUID) status experimental/test/stable/deprecated description Detailed description author Rule author date Creation date modified Last modification references URLs for more info tags MITRE ATT&CK tags falsepositives Known false positives level informational/low/medium/high/critical
LOG SOURCES#
WINDOWS#
logsource:
product: windows
service: security
logsource:
product: windows
service: system
logsource:
product: windows
service: sysmon
logsource:
category: process_creation
product: windows
logsource:
category: network_connection
product: windows
logsource:
category: file_event
product: windows
logsource:
category: registry_event
product: windows
logsource:
category: ps_script
product: windows
LINUX#
logsource:
product: linux
service: auth
logsource:
product: linux
service: syslog
logsource:
category: process_creation
product: linux
FIREWALL#
logsource:
category: firewall
PROXY/WEB#
logsource:
category: proxy
logsource:
category: webserver
DETECTION LOGIC#
SELECTION#
detection:
selection:
FieldName: 'value'
condition: selection
MULTIPLE VALUES#
detection:
selection:
FieldName:
- 'value1'
- 'value2'
- 'value3'
condition: selection
MULTIPLE FIELDS#
detection:
selection:
Field1: 'value1'
Field2: 'value2'
condition: selection # AND logic
MODIFIERS#
contains Field contains value startswith Field starts with endswith Field ends with all All values must match base64 Base64 encoded base64offset Base64 with offset re Regular expression cidr CIDR notation lt/lte/gt/gte Numeric comparison expand Expand placeholders
MODIFIER EXAMPLES#
detection:
selection:
CommandLine|contains: 'mimikatz'
Image|endswith: '\powershell.exe'
DestinationIp|cidr: '10.0.0.0/8'
CommandLine|base64: 'decoded_string'
Message|re: 'error.*failed'
CONDITIONS#
condition: selection # Simple condition: selection1 or selection2 # OR condition: selection1 and selection2 # AND condition: selection and not filter # Exclude condition: 1 of selection* # Any of condition: all of selection* # All of condition: selection | count() > 10 # Aggregation
FILTERS#
detection:
selection:
Image|endswith: '\powershell.exe'
filter:
User: 'SYSTEM'
ParentImage|endswith: '\svchost.exe'
condition: selection and not filter
AGGREGATION#
detection:
selection:
EventID: 4625
condition: selection | count(TargetUserName) by SourceIP > 10
timeframe: 5m
EXAMPLE RULES#
PROCESS CREATION#
title: Suspicious PowerShell Encoded Command
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- '-enc'
- '-encodedcommand'
- 'frombase64'
condition: selection
level: high
NETWORK CONNECTION#
title: Outbound Connection to Suspicious Port
logsource:
category: network_connection
product: windows
detection:
selection:
Initiated: 'true'
DestinationPort:
- 4444
- 5555
- 8888
condition: selection
level: medium
REGISTRY#
title: Registry Run Key Modification
logsource:
category: registry_event
product: windows
detection:
selection:
EventType: SetValue
TargetObject|contains: '\CurrentVersion\Run'
condition: selection
level: medium
FILE EVENT#
title: Executable in Suspicious Location
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith: '.exe'
TargetFilename|contains:
- '\Temp\'
- '\AppData\Local\Temp\'
condition: selection
level: low
AUTHENTICATION#
title: Multiple Failed Logins
logsource:
product: windows
service: security
detection:
selection:
EventID: 4625
condition: selection | count(TargetUserName) by IpAddress > 5
timeframe: 5m
level: medium
CONVERTING RULES#
SIGMA-CLI#
# List backends sigma list backends # Convert to Splunk sigma convert -t splunk rule.yml # Convert to Elasticsearch sigma convert -t elasticsearch rule.yml # Convert directory sigma convert -t splunk rules/ -o output/ # With pipeline sigma convert -t splunk -p sysmon rule.yml
SUPPORTED BACKENDS#
splunk Splunk SPL elasticsearch Elasticsearch DSL/Lucene qradar IBM QRadar AQL sentinel Microsoft Sentinel KQL chronicle Google Chronicle crowdstrike CrowdStrike insightidr Rapid7 InsightIDR
PIPELINES#
# Processing pipelines sigma convert -t splunk -p sysmon rule.yml sigma convert -t splunk -p windows rule.yml
MITRE ATT&CK TAGS#
TACTICS#
attack.initial_access attack.execution attack.persistence attack.privilege_escalation attack.defense_evasion attack.credential_access attack.discovery attack.lateral_movement attack.collection attack.exfiltration attack.command_and_control
TECHNIQUE EXAMPLES#
attack.t1059.001 # PowerShell attack.t1059.003 # Windows Command Shell attack.t1053.005 # Scheduled Task attack.t1003.001 # LSASS Memory attack.t1021.001 # RDP attack.t1021.006 # WinRM attack.t1105 # Ingress Tool Transfer
VALIDATION#
# Validate rule sigma check rule.yml # Validate directory sigma check rules/
RESOURCES#
# Official repository https://github.com/SigmaHQ/sigma # Rule database https://github.com/SigmaHQ/sigma/tree/master/rules
QUICK REFERENCE#
# Basic rule structure
title: Name
logsource:
category: process_creation
product: windows
detection:
selection:
Field|modifier: value
condition: selection
level: high
# Convert
sigma convert -t splunk rule.yml
sigma convert -t elasticsearch rule.yml
# Validate
sigma check rule.yml
SIGMA RULES CHEATSHEET
======================
Source: https://cheatsheet.johlem.net
Sigma is a generic signature format for SIEM systems.
Write once, convert to Splunk, Elastic, QRadar, etc.
INSTALLATION
------------
pip install sigma-cli
pip install pySigma
# With backends
pip install pySigma-backend-splunk
pip install pySigma-backend-elasticsearch
RULE STRUCTURE
==============
BASIC TEMPLATE
--------------
title: Rule Title
id: UUID-here
status: experimental
description: Description of what the rule detects
author: Your Name
date: 2024/01/01
modified: 2024/01/15
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains: '-enc'
condition: selection
falsepositives:
- Administrative scripts
level: high
tags:
- attack.execution
- attack.t1059.001
REQUIRED FIELDS
---------------
title Rule name
logsource Log source definition
detection Detection logic
OPTIONAL FIELDS
---------------
id Unique identifier (UUID)
status experimental/test/stable/deprecated
description Detailed description
author Rule author
date Creation date
modified Last modification
references URLs for more info
tags MITRE ATT&CK tags
falsepositives Known false positives
level informational/low/medium/high/critical
LOG SOURCES
===========
WINDOWS
-------
logsource:
product: windows
service: security
logsource:
product: windows
service: system
logsource:
product: windows
service: sysmon
logsource:
category: process_creation
product: windows
logsource:
category: network_connection
product: windows
logsource:
category: file_event
product: windows
logsource:
category: registry_event
product: windows
logsource:
category: ps_script
product: windows
LINUX
-----
logsource:
product: linux
service: auth
logsource:
product: linux
service: syslog
logsource:
category: process_creation
product: linux
FIREWALL
--------
logsource:
category: firewall
PROXY/WEB
---------
logsource:
category: proxy
logsource:
category: webserver
DETECTION LOGIC
===============
SELECTION
---------
detection:
selection:
FieldName: 'value'
condition: selection
MULTIPLE VALUES
---------------
detection:
selection:
FieldName:
- 'value1'
- 'value2'
- 'value3'
condition: selection
MULTIPLE FIELDS
---------------
detection:
selection:
Field1: 'value1'
Field2: 'value2'
condition: selection # AND logic
MODIFIERS
---------
contains Field contains value
startswith Field starts with
endswith Field ends with
all All values must match
base64 Base64 encoded
base64offset Base64 with offset
re Regular expression
cidr CIDR notation
lt/lte/gt/gte Numeric comparison
expand Expand placeholders
MODIFIER EXAMPLES
-----------------
detection:
selection:
CommandLine|contains: 'mimikatz'
Image|endswith: '\powershell.exe'
DestinationIp|cidr: '10.0.0.0/8'
CommandLine|base64: 'decoded_string'
Message|re: 'error.*failed'
CONDITIONS
----------
condition: selection # Simple
condition: selection1 or selection2 # OR
condition: selection1 and selection2 # AND
condition: selection and not filter # Exclude
condition: 1 of selection* # Any of
condition: all of selection* # All of
condition: selection | count() > 10 # Aggregation
FILTERS
-------
detection:
selection:
Image|endswith: '\powershell.exe'
filter:
User: 'SYSTEM'
ParentImage|endswith: '\svchost.exe'
condition: selection and not filter
AGGREGATION
-----------
detection:
selection:
EventID: 4625
condition: selection | count(TargetUserName) by SourceIP > 10
timeframe: 5m
EXAMPLE RULES
=============
PROCESS CREATION
----------------
title: Suspicious PowerShell Encoded Command
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- '-enc'
- '-encodedcommand'
- 'frombase64'
condition: selection
level: high
NETWORK CONNECTION
------------------
title: Outbound Connection to Suspicious Port
logsource:
category: network_connection
product: windows
detection:
selection:
Initiated: 'true'
DestinationPort:
- 4444
- 5555
- 8888
condition: selection
level: medium
REGISTRY
--------
title: Registry Run Key Modification
logsource:
category: registry_event
product: windows
detection:
selection:
EventType: SetValue
TargetObject|contains: '\CurrentVersion\Run'
condition: selection
level: medium
FILE EVENT
----------
title: Executable in Suspicious Location
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith: '.exe'
TargetFilename|contains:
- '\Temp\'
- '\AppData\Local\Temp\'
condition: selection
level: low
AUTHENTICATION
--------------
title: Multiple Failed Logins
logsource:
product: windows
service: security
detection:
selection:
EventID: 4625
condition: selection | count(TargetUserName) by IpAddress > 5
timeframe: 5m
level: medium
CONVERTING RULES
================
SIGMA-CLI
---------
# List backends
sigma list backends
# Convert to Splunk
sigma convert -t splunk rule.yml
# Convert to Elasticsearch
sigma convert -t elasticsearch rule.yml
# Convert directory
sigma convert -t splunk rules/ -o output/
# With pipeline
sigma convert -t splunk -p sysmon rule.yml
SUPPORTED BACKENDS
------------------
splunk Splunk SPL
elasticsearch Elasticsearch DSL/Lucene
qradar IBM QRadar AQL
sentinel Microsoft Sentinel KQL
chronicle Google Chronicle
crowdstrike CrowdStrike
insightidr Rapid7 InsightIDR
PIPELINES
---------
# Processing pipelines
sigma convert -t splunk -p sysmon rule.yml
sigma convert -t splunk -p windows rule.yml
MITRE ATT&CK TAGS
=================
TACTICS
-------
attack.initial_access
attack.execution
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.credential_access
attack.discovery
attack.lateral_movement
attack.collection
attack.exfiltration
attack.command_and_control
TECHNIQUE EXAMPLES
------------------
attack.t1059.001 # PowerShell
attack.t1059.003 # Windows Command Shell
attack.t1053.005 # Scheduled Task
attack.t1003.001 # LSASS Memory
attack.t1021.001 # RDP
attack.t1021.006 # WinRM
attack.t1105 # Ingress Tool Transfer
VALIDATION
==========
# Validate rule
sigma check rule.yml
# Validate directory
sigma check rules/
RESOURCES
=========
# Official repository
https://github.com/SigmaHQ/sigma
# Rule database
https://github.com/SigmaHQ/sigma/tree/master/rules
QUICK REFERENCE
---------------
# Basic rule structure
title: Name
logsource:
category: process_creation
product: windows
detection:
selection:
Field|modifier: value
condition: selection
level: high
# Convert
sigma convert -t splunk rule.yml
sigma convert -t elasticsearch rule.yml
# Validate
sigma check rule.yml
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.