Detection Engineering with Sigma
Sigma is an open and generic format to share log detection signatures. In this hands-on workshop we learn what Sigma is and how to write good Sigma rules including correlations by developing some for existing threats. Furthermore, we will explore the advantages and shortcomings of developing rules with LLMs and how results can be improved by usage of the Sigma MCP server.
This workshop covers the following topics:
- Introduction to Sigma
- Components of a Sigma rule
- Conventions & good practices
- Tools: Sigma VSCode Extension & sigconverter.io
- Sigma correlation rules
- Writing Sigma & Sigma correlation rules
- Using LLMs in Sigma detection engineering
- Comparison of LLM results
- Improving LLM results by usage of the new Sigma MCP server
Thomas has 20 years experience in information security and has done lots of stuff in this area, from offensive to defensive security topics. Now he is doing incident response, threat hunting and threat intelligence at the Evonik Cyber Defense Team. Furthermore, he is co-founder of the Sigma project and maintains the open source toolchain (pySigma/Sigma CLI/Sigma MCP server).