Tag: Sigma translation

Detect Linux Reconnaissance in Microsoft Sentinel with Sigma-to-KQL Conversion
Detect Linux Reconnaissance in Microsoft Sentinel with Sigma-to-KQL Conversion

How It Works The showcased feature translates a Linux-based Sigma rule — specifically targeting the sysinfo system call — into Microsoft Sentinel KQL. This system call provides an attacker with system metadata like uptime, memory usage, and load averages — commonly abused during reconnaissance. Left Panel – Sigma Rule: Targets Linux auditd telemetry for syscall […]

Read More
Cross-Platform Rule Translation: From Sigma to CrowdStrike with Uncoder AI
Cross-Platform Rule Translation: From Sigma to CrowdStrike with Uncoder AI

Cross-Platform Rule Translation: From Sigma to CrowdStrike with Uncoder AI How It Works Uncoder AI takes structured detection content written in Sigma, a popular open detection rule format, and automatically converts it into platform-specific logic — in this case, CrowdStrike Endpoint Search syntax. The Sigma rule describes a technique where Deno (a secure JavaScript runtime) […]

Read More