Sigma rule processing and conversion tools
Project description
pySigma
pySigma is a python library that parses and converts Sigma rules into queries. It is a replacement
for the legacy Sigma toolchain (sigmac) with a much cleaner design and is almost fully tested.
Backends for support of conversion into query languages and processing pipelines for transforming
rule for log data models are separated into dedicated projects to keep pySigma itself slim and
vendor-agnostic. See the Related Projects section below to get an overview.
Getting Started
To start using pySigma, you need Python 3.10 or later. Install it using your python package manager of choice. Examples:
pip install pysigma
pipenv install pysigma
poetry add pysigma
Documentation with some usage examples can be found here.
Create Your Own Backend for pySigma
The creation of a backend has become much easier with pySigma. We recommend using the "Cookie Cutter Template" and reviewing the existing backends listed in the "Related Projects" section of this README.
pySigma Cookie Cutter Template
Features
pySigma brings a number of additional features compared to the all in one sigmac, as well as some changes.
sigma-cli is the equivalent of sigmac for command-line conversion
Modifier
use sigma list modifiers
Backends
use sigma plugin list --plugin-type backend
Overview
Conversion Overview
Pipelines
More details are described in the documentation.
Testing
pySigma uses pytest as testing framework. Simply run pytest to run all tests. Run pytest --cov=sigma to get a coverage report.
Building
To build your own package run poetry build.
Linting
To lint the code run poetry run black. To check for linting errors run poetry run black --check.
This project also uses pre-commit, which is installed by poetry as part of dev dependencies. To install the git hooks run poetry run pre-commit install after cloning the repository and installing the dependencies.
Contributing
Pull requests are welcome. Please feel free to lodge any issues/PRs as discussion points.
This blog post by Micah Babinski explains the process from a developer's perspective.
Maintainers
The project is currently maintained by:
- Thomas Patzke thomas@patzke.org
- François Hubaut
Related Projects
pySigma isn't a monolithic library attempting to support everything but the core. Support for target query languages and log data models is provided by additional packages that extend pySigma:
- sigma-cli: a command line interface for conversion of Sigma rules based on pySigma.
- pySigma-backend-splunk
- pySigma-pipeline-sysmon
- pySigma-pipeline-crowdstrike
- pySigma-backend-netwitness
- pySigma-backend-panther
All packages can also be installed from PyPI if not mentioned otherwise by the Python package manager of your choice.
License
GNU Lesser General Public License v2.1. For details, please see the full license file located here.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pysigma-1.1.0.tar.gz.
File metadata
- Download URL: pysigma-1.1.0.tar.gz
- Upload date:
- Size: 126.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4ff157f2ce0d24beacd89176b74643aab72e6b32f10966e731ab0ddff4f96451
|
|
| MD5 |
0ec942814cc7a08630332716dc5b5117
|
|
| BLAKE2b-256 |
4d8c6a8fef80ac86295eee28364d45168e8a1ed0940bf1c10c442c3bead579bf
|
Provenance
The following attestation bundles were made for pysigma-1.1.0.tar.gz:
Publisher:
release.yml on SigmaHQ/pySigma
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pysigma-1.1.0.tar.gz -
Subject digest:
4ff157f2ce0d24beacd89176b74643aab72e6b32f10966e731ab0ddff4f96451 - Sigstore transparency entry: 806273190
- Sigstore integration time:
-
Permalink:
SigmaHQ/pySigma@f8313ab6045672b15360b9f9483a7a34f2484367 -
Branch / Tag:
refs/tags/v1.1.0 - Owner: https://github.com/SigmaHQ
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f8313ab6045672b15360b9f9483a7a34f2484367 -
Trigger Event:
release
-
Statement type:
File details
Details for the file pysigma-1.1.0-py3-none-any.whl.
File metadata
- Download URL: pysigma-1.1.0-py3-none-any.whl
- Upload date:
- Size: 155.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
41eb420dafa1f97f2898732e6849232099833bb3bb7ebf219257fb0596c7ef05
|
|
| MD5 |
28aee0652d60a7fb229779ae02365ba2
|
|
| BLAKE2b-256 |
1de6012d64a6eb7b1cdd2ef21de4fa1ec69880e821e7ea06fef3b6823d604637
|
Provenance
The following attestation bundles were made for pysigma-1.1.0-py3-none-any.whl:
Publisher:
release.yml on SigmaHQ/pySigma
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pysigma-1.1.0-py3-none-any.whl -
Subject digest:
41eb420dafa1f97f2898732e6849232099833bb3bb7ebf219257fb0596c7ef05 - Sigstore transparency entry: 806273269
- Sigstore integration time:
-
Permalink:
SigmaHQ/pySigma@f8313ab6045672b15360b9f9483a7a34f2484367 -
Branch / Tag:
refs/tags/v1.1.0 - Owner: https://github.com/SigmaHQ
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f8313ab6045672b15360b9f9483a7a34f2484367 -
Trigger Event:
release
-
Statement type: