Thomas Patzke
Thomas has 20 years experience in information security and has done lots of stuff in this area, from offensive to defensive security topics. Now he is doing incident response, threat hunting and threat intelligence at the Evonik Cyber Defense Team. Furthermore, he is co-founder of the Sigma project and maintains the open source toolchain (pySigma/Sigma CLI/Sigma MCP server).
Session
Sigma is an open and generic format to share log detection signatures. In this hands-on workshop we learn what Sigma is and how to write good Sigma rules including correlations by developing some for existing threats. Furthermore, we will explore the advantages and shortcomings of developing rules with LLMs and how results can be improved by usage of the Sigma MCP server.