← All cheat sheets

SIGMA RULES

Plain-text reference · 7 KB. Read it, search it (Ctrl-F) or print it.

Sigma is a generic signature format for SIEM systems.
Write once, convert to Splunk, Elastic, QRadar, etc.

INSTALLATION#

pip install sigma-cli
pip install pySigma

# With backends
pip install pySigma-backend-splunk
pip install pySigma-backend-elasticsearch

RULE STRUCTURE#


            

BASIC TEMPLATE#

title: Rule Title
id: UUID-here
status: experimental
description: Description of what the rule detects
author: Your Name
date: 2024/01/01
modified: 2024/01/15

logsource:
    category: process_creation
    product: windows

detection:
    selection:
        Image|endswith: '\powershell.exe'
        CommandLine|contains: '-enc'
    condition: selection

falsepositives:
    - Administrative scripts
level: high

tags:
    - attack.execution
    - attack.t1059.001

REQUIRED FIELDS#

title           Rule name
logsource       Log source definition
detection       Detection logic

OPTIONAL FIELDS#

id              Unique identifier (UUID)
status          experimental/test/stable/deprecated
description     Detailed description
author          Rule author
date            Creation date
modified        Last modification
references      URLs for more info
tags            MITRE ATT&CK tags
falsepositives  Known false positives
level           informational/low/medium/high/critical

LOG SOURCES#


            

WINDOWS#

logsource:
    product: windows
    service: security

logsource:
    product: windows
    service: system

logsource:
    product: windows
    service: sysmon

logsource:
    category: process_creation
    product: windows

logsource:
    category: network_connection
    product: windows

logsource:
    category: file_event
    product: windows

logsource:
    category: registry_event
    product: windows

logsource:
    category: ps_script
    product: windows

LINUX#

logsource:
    product: linux
    service: auth

logsource:
    product: linux
    service: syslog

logsource:
    category: process_creation
    product: linux

FIREWALL#

logsource:
    category: firewall

PROXY/WEB#

logsource:
    category: proxy

logsource:
    category: webserver

DETECTION LOGIC#


            

SELECTION#

detection:
    selection:
        FieldName: 'value'
    condition: selection

MULTIPLE VALUES#

detection:
    selection:
        FieldName:
            - 'value1'
            - 'value2'
            - 'value3'
    condition: selection

MULTIPLE FIELDS#

detection:
    selection:
        Field1: 'value1'
        Field2: 'value2'
    condition: selection        # AND logic

MODIFIERS#

contains            Field contains value
startswith          Field starts with
endswith            Field ends with
all                 All values must match
base64              Base64 encoded
base64offset        Base64 with offset
re                  Regular expression
cidr                CIDR notation
lt/lte/gt/gte       Numeric comparison
expand              Expand placeholders

MODIFIER EXAMPLES#

detection:
    selection:
        CommandLine|contains: 'mimikatz'
        Image|endswith: '\powershell.exe'
        DestinationIp|cidr: '10.0.0.0/8'
        CommandLine|base64: 'decoded_string'
        Message|re: 'error.*failed'

CONDITIONS#

condition: selection                    # Simple
condition: selection1 or selection2     # OR
condition: selection1 and selection2    # AND
condition: selection and not filter     # Exclude
condition: 1 of selection*              # Any of
condition: all of selection*            # All of
condition: selection | count() > 10     # Aggregation

FILTERS#

detection:
    selection:
        Image|endswith: '\powershell.exe'
    filter:
        User: 'SYSTEM'
        ParentImage|endswith: '\svchost.exe'
    condition: selection and not filter

AGGREGATION#

detection:
    selection:
        EventID: 4625
    condition: selection | count(TargetUserName) by SourceIP > 10
    timeframe: 5m

EXAMPLE RULES#


            

PROCESS CREATION#

title: Suspicious PowerShell Encoded Command
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith: '\powershell.exe'
        CommandLine|contains:
            - '-enc'
            - '-encodedcommand'
            - 'frombase64'
    condition: selection
level: high

NETWORK CONNECTION#

title: Outbound Connection to Suspicious Port
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Initiated: 'true'
        DestinationPort:
            - 4444
            - 5555
            - 8888
    condition: selection
level: medium

REGISTRY#

title: Registry Run Key Modification
logsource:
    category: registry_event
    product: windows
detection:
    selection:
        EventType: SetValue
        TargetObject|contains: '\CurrentVersion\Run'
    condition: selection
level: medium

FILE EVENT#

title: Executable in Suspicious Location
logsource:
    category: file_event
    product: windows
detection:
    selection:
        TargetFilename|endswith: '.exe'
        TargetFilename|contains:
            - '\Temp\'
            - '\AppData\Local\Temp\'
    condition: selection
level: low

AUTHENTICATION#

title: Multiple Failed Logins
logsource:
    product: windows
    service: security
detection:
    selection:
        EventID: 4625
    condition: selection | count(TargetUserName) by IpAddress > 5
    timeframe: 5m
level: medium

CONVERTING RULES#


            

SIGMA-CLI#

# List backends
sigma list backends

# Convert to Splunk
sigma convert -t splunk rule.yml

# Convert to Elasticsearch
sigma convert -t elasticsearch rule.yml

# Convert directory
sigma convert -t splunk rules/ -o output/

# With pipeline
sigma convert -t splunk -p sysmon rule.yml

SUPPORTED BACKENDS#

splunk              Splunk SPL
elasticsearch       Elasticsearch DSL/Lucene
qradar              IBM QRadar AQL
sentinel            Microsoft Sentinel KQL
chronicle           Google Chronicle
crowdstrike         CrowdStrike
insightidr          Rapid7 InsightIDR

PIPELINES#

# Processing pipelines
sigma convert -t splunk -p sysmon rule.yml
sigma convert -t splunk -p windows rule.yml

MITRE ATT&CK TAGS#


            

TACTICS#

attack.initial_access
attack.execution
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.credential_access
attack.discovery
attack.lateral_movement
attack.collection
attack.exfiltration
attack.command_and_control

TECHNIQUE EXAMPLES#

attack.t1059.001    # PowerShell
attack.t1059.003    # Windows Command Shell
attack.t1053.005    # Scheduled Task
attack.t1003.001    # LSASS Memory
attack.t1021.001    # RDP
attack.t1021.006    # WinRM
attack.t1105        # Ingress Tool Transfer

VALIDATION#

# Validate rule
sigma check rule.yml

# Validate directory
sigma check rules/

RESOURCES#

# Official repository
https://github.com/SigmaHQ/sigma

# Rule database
https://github.com/SigmaHQ/sigma/tree/master/rules

QUICK REFERENCE#

# Basic rule structure
title: Name
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Field|modifier: value
    condition: selection
level: high

# Convert
sigma convert -t splunk rule.yml
sigma convert -t elasticsearch rule.yml

# Validate
sigma check rule.yml

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.