Detection as code
CI validates Sigma rule syntax and compiles it to KQL for Microsoft Sentinel and Defender on every commit, and nothing merges until it passes. Each rule ships beside its false-positive analysis and validation steps.
Four detections mapped to MITRE ATT&CK: password spray (T1110.003), brute force (T1110.001), malicious inbox rule creation (T1098), and impossible travel.
Author and maintainer.
- Source
- Sigma
- Compile
- KQL
- Deploy
- Sentinel