AttackIQ/SigmAIQ

A pySigma wrapper and langchain toolkit for automatic rule creation/translation

44
/ 100
Emerging

This tool helps security detection engineers convert Sigma rules into queries for various Security Information and Event Management (SIEM) systems like Splunk or Microsoft 365 Defender. You provide a standard Sigma detection rule, and it outputs a ready-to-use query tailored for your specific SIEM platform. This is for detection engineers who write or manage threat detection rules.

Use this if you need to quickly and accurately translate generic Sigma detection rules into specific queries for different SIEM systems without manual adjustments.

Not ideal if you are looking for a general-purpose programming library or if your primary need is not converting Sigma rules for SIEM platforms.

threat-detection SIEM-engineering security-operations rule-translation cybersecurity
No Package No Dependents
Maintenance 6 / 25
Adoption 9 / 25
Maturity 16 / 25
Community 13 / 25

How are scores calculated?

Stars

92

Forks

11

Language

Python

License

LGPL-2.1

Last pushed

Nov 03, 2025

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/llm-tools/AttackIQ/SigmAIQ"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.