Hand-writing detection rules from a blank file is the slowest part of the job.
RSigma v0.19.0 is out, taking the Rust Sigma engine from "here are some suspicious events" to "here's a tested draft rule":
• Rule drafting from logs: feed it a few exemplar events, get back paste-ready Sigma YAML, already compiled and matched against those events so it can't hand you an over-broad rule. You review, you decide.
• Schema signature discovery: turn unknown events into ranked, reviewable schema signatures instead of writing each one by hand
• Locked-down daemon control plane: opt-in bearer-token auth, resource:action RBAC, and an append-only audit trail of who changed what
• rstix, the STIX 2.1 threat-intel library, now on crates.io with full pattern evaluation and a twelve-check validation pipeline
• New docs home at rsigma.io, with search
Yes, an AI agent can draft you a Sigma rule too. RSigma does it differently: deterministic, glass-box data mining over your actual events, not a guess from a model. It profiles every field, drops the volatile ones, and scores what survives by stability and rarity against your baseline. Then every draft is parsed and compiled through the real evaluation engine and matched against your exemplars before you ever see it, with a false-positive estimate from a baseline run and the logsource inferred from its own schema classifier. Same events in, byte-identical rule out. No hallucinated fields, nothing to babysit.
Fast, single-binary, open source.
Try it, break it, and tell me what you think. Feedback and testers very welcome.
Repo: https://github.com/timescale/rsigma
Release notes: https://github.com/timescale/rsigma/releases/tag/v0.19.0
Remote
Mostafa Moradian
@mostafa@infosec.exchange
Lead Security Engineer at Tiger Data | Securing and shipping cool stuff
0 Followers
0 Following
4 Posts
Joined January 18, 2023
Twitter:
Personal Blog:
GitHub:
Open post
RSigma is now listed under Security Tools on awesome-rust: https://github.com/rust-unofficial/awesome-rust
0
0
0
0
Open post
Your best detections are trapped in one vendor's query language.
RSigma v0.20.0 is out, and the Rust Sigma engine now runs both directions: from Sigma to your SIEM, and from your SIEM back to portable Sigma.
• Reverse conversion: paste an Elastic/Lucene query, get back clean Sigma YAML you can version, share, and convert anywhere else. Every drafted rule is parsed back before you see it, so a rule that won't round-trip never reaches you. In the CLI as "rsigma rule reverse", and over MCP as "reverse_convert".
• A real intermediate representation: a new IR crate is now the backbone for both compile and convert. Same rule in, byte-identical backend output, just cleaner and faster underneath.
• rstix, the STIX 2.1 threat-intel library, gets a TAXII 2.1 client: pull intel over mTLS with pagination, auth, and retries, alongside new graph traversal, TLP marking, and an object store.
• Cloud coverage: schema signatures now auto-route AWS CloudTrail and VPC Flow, Azure, GCP, Microsoft 365, GitHub, Okta, OneLogin, Kubernetes, Docker, and osquery events to the right logsource, no hand-tagging.
Migrating detections between SIEMs is usually a rewrite-by-hand slog, or a lossy script that hands you YAML you can't trust. RSigma does it differently: deterministic and glass-box. It parses your query into a typed IR, raises it to a Sigma rule, and round-trips every draft through the parser before printing. If a construct can't be expressed, you get a structured error, not a silently broken rule.
Fast, single-binary, open source.
Try it, break it, and tell me what you think. Feedback and testers very welcome.
Repo: https://github.com/timescale/rsigma
Release notes: https://github.com/timescale/rsigma/releases/tag/v0.20.0
0
0
0
0
Open post
You can try the latest version of RSigma MCP directly in your browser against the entire Sigma rules repository on Glama.ai. No need to install anything!
https://glama.ai/mcp/servers/timescale/rsigma
These tools are provided: https://rsigma.io/guide/mcp-server/#mcp-server-tool-reference
0
0
0
0