Skip to main content

droid

droid is a PySigma wrapper allowing an easy adoption of Sigma and helps enabling Detection-As-Code. The ultimate goal of droid is to consume a repository Sigma rules and deploy them on one or multiple platform (SIEM/EDR). The tool also supports plain SIEM/EDR search queries.

droid workflow

🚀 Features

Key features are:

  1. Validate the syntax of Sigma rules
  2. Convert them by applying a set of transforms per log source and platform
  3. Search in logs and report on findings
  4. Test the rules by leveraging Atomic Red Team™ (work in progress)
  5. Deploy them with any compatible SIEM and EDR (.e.g. Splunk, Microsoft Sentinel)

🚂 Get started

To get started with the tool, visit the documentation page and configure droid for your environment.

Note: Python version 3.11.8+ is required

📚 Resources

License

Licensed under the EUPL.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

detect_droid-0.3.3.tar.gz (56.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

detect_droid-0.3.3-py3-none-any.whl (65.5 kB view details)

Uploaded Python 3

File details

Details for the file detect_droid-0.3.3.tar.gz.

File metadata

  • Download URL: detect_droid-0.3.3.tar.gz
  • Upload date:
  • Size: 56.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for detect_droid-0.3.3.tar.gz
Algorithm Hash digest
SHA256 6250188da22f4825c679aa116207e2d2e45bd4475a995524f54d37f49139bfeb
MD5 0f29ae14d48da281c2dd4e273a3b1ef0
BLAKE2b-256 77de2c85b79b06659768555d8902b9df63466954c5c44f19e2af61b6c88f50aa

See more details on using hashes here.

File details

Details for the file detect_droid-0.3.3-py3-none-any.whl.

File metadata

  • Download URL: detect_droid-0.3.3-py3-none-any.whl
  • Upload date:
  • Size: 65.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for detect_droid-0.3.3-py3-none-any.whl
Algorithm Hash digest
SHA256 18e68822a8e1b75855b93fee1f947ee938830078c5437f46ac7ebd3ecd856fb0
MD5 6d474b694d0bf03ee1aa84b505762f79
BLAKE2b-256 7bf8f988d001011b08e26c9f73060250e48c15eaff37151efcaea3e5051b0545

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.3.3 This release

2 files

0.3.2

2 files

0.3.1

2 files

0.3.0

2 files

0.2.21

2 files

0.2.20

2 files

0.2.19

2 files

0.2.18

2 files

0.2.17

2 files

0.2.16

2 files

0.2.15

2 files

0.2.14

2 files

0.2.13

2 files

0.2.12

2 files

0.2.11

2 files

0.2.10

2 files

0.2.9

2 files

0.2.8

2 files

0.2.7

2 files

0.2.6

2 files

0.2.5

2 files

0.2.4

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page