Skip to main content

No project description provided

Project description

sigma-rule-matcher

Here's a revised version of the high-level explanation for your README:


What is this?

sigma-rule-matcher is a Python package for evaluating Sigma detection rules against structured event data. Built on top of PySigma, it parses and applies Sigma rule logic—including condition expressions and most common modifiers—to incoming events to determine whether they match.

The project is primarily a learning tool, hacked together to better understand how Sigma rules operate under the hood.


License

This project is licensed under the MIT License.

It uses the pySigma library, which is licensed under the GNU Lesser General Public License v2.1 (LGPL-2.1). A copy of the LGPL-2.1 license is here.

We use pySigma without modification.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sigma_rule_matcher-0.0.1.tar.gz (14.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sigma_rule_matcher-0.0.1-py3-none-any.whl (10.1 kB view details)

Uploaded Python 3

File details

Details for the file sigma_rule_matcher-0.0.1.tar.gz.

File metadata

  • Download URL: sigma_rule_matcher-0.0.1.tar.gz
  • Upload date:
  • Size: 14.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: python-httpx/0.28.1

File hashes

Hashes for sigma_rule_matcher-0.0.1.tar.gz
Algorithm Hash digest
SHA256 fa6ae1127c406f88fba38ef9136585860f21816585d66cc92a74d47425de5cba
MD5 7cb179b97934adacd658d709bf793776
BLAKE2b-256 de76107890ffd06b593668da7889eaa6a6c8fdb9cce0f3fd722ea36cc20ff4bc

See more details on using hashes here.

File details

Details for the file sigma_rule_matcher-0.0.1-py3-none-any.whl.

File metadata

File hashes

Hashes for sigma_rule_matcher-0.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 61aa017777b499c7f6950c285a0225402f637ae1bbaa5338cca521b913d2cc79
MD5 509c0dae20cb735d270aad5147efb9f0
BLAKE2b-256 f517a9e0114ab036c9944669684cdc5a4b3fb204bb3aa5a20a5ddead2dd3297f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page