Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Mostafa Moradian

@mostafa@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Lead Security Engineer at Tiger Data | Securing and shipping cool stuff

0 Followers
0 Following
4 Posts
Joined January 18, 2023
Twitter:
https://twitter.com/MosiMoradian
LinkedIn:
https://www.linkedin.com/in/mostafa-moradian/
Personal Blog:
https://mostafa.dev/
GitHub:
https://github.com/mostafa
Open post
Mostafa Moradian @mostafa@infosec.exchange
· 2mo ago
Hand-writing detection rules from a blank file is the slowest part of the job. RSigma v0.19.0 is out, taking the Rust Sigma engine from "here are some suspicious events" to "here's a tested draft rule": • Rule drafting from logs: feed it a few exemplar events, get back paste-ready Sigma YAML, already compiled and matched against those events so it can't hand you an over-broad rule. You review, you decide. • Schema signature discovery: turn unknown events into ranked, reviewable schema signatures instead of writing each one by hand • Locked-down daemon control plane: opt-in bearer-token auth, resource:action RBAC, and an append-only audit trail of who changed what • rstix, the STIX 2.1 threat-intel library, now on crates.io with full pattern evaluation and a twelve-check validation pipeline • New docs home at rsigma.io, with search Yes, an AI agent can draft you a Sigma rule too. RSigma does it differently: deterministic, glass-box data mining over your actual events, not a guess from a model. It profiles every field, drops the volatile ones, and scores what survives by stability and rarity against your baseline. Then every draft is parsed and compiled through the real evaluation engine and matched against your exemplars before you ever see it, with a false-positive estimate from a baseline run and the logsource inferred from its own schema classifier. Same events in, byte-identical rule out. No hallucinated fields, nothing to babysit. Fast, single-binary, open source. Try it, break it, and tell me what you think. Feedback and testers very welcome. Repo: https://github.com/timescale/rsigma Release notes: https://github.com/timescale/rsigma/releases/tag/v0.19.0
github.com
0
0
0
0
Open post
Mostafa Moradian @mostafa@infosec.exchange
· 2mo ago
RSigma is now listed under Security Tools on awesome-rust: https://github.com/rust-unofficial/awesome-rust
GitHub

GitHub - rust-unofficial/awesome-rust: A curated list of Rust code and resources.

A curated list of Rust code and resources. Contribute to rust-unofficial/awesome-rust development by creating an account on GitHub.

0
0
0
0
Open post
Mostafa Moradian @mostafa@infosec.exchange
· 2mo ago
Your best detections are trapped in one vendor's query language. RSigma v0.20.0 is out, and the Rust Sigma engine now runs both directions: from Sigma to your SIEM, and from your SIEM back to portable Sigma. • Reverse conversion: paste an Elastic/Lucene query, get back clean Sigma YAML you can version, share, and convert anywhere else. Every drafted rule is parsed back before you see it, so a rule that won't round-trip never reaches you. In the CLI as "rsigma rule reverse", and over MCP as "reverse_convert". • A real intermediate representation: a new IR crate is now the backbone for both compile and convert. Same rule in, byte-identical backend output, just cleaner and faster underneath. • rstix, the STIX 2.1 threat-intel library, gets a TAXII 2.1 client: pull intel over mTLS with pagination, auth, and retries, alongside new graph traversal, TLP marking, and an object store. • Cloud coverage: schema signatures now auto-route AWS CloudTrail and VPC Flow, Azure, GCP, Microsoft 365, GitHub, Okta, OneLogin, Kubernetes, Docker, and osquery events to the right logsource, no hand-tagging. Migrating detections between SIEMs is usually a rewrite-by-hand slog, or a lossy script that hands you YAML you can't trust. RSigma does it differently: deterministic and glass-box. It parses your query into a typed IR, raises it to a Sigma rule, and round-trips every draft through the parser before printing. If a construct can't be expressed, you get a structured error, not a silently broken rule. Fast, single-binary, open source. Try it, break it, and tell me what you think. Feedback and testers very welcome. Repo: https://github.com/timescale/rsigma Release notes: https://github.com/timescale/rsigma/releases/tag/v0.20.0
github.com
0
0
0
0
Open post
Mostafa Moradian @mostafa@infosec.exchange
· 2mo ago
You can try the latest version of RSigma MCP directly in your browser against the entire Sigma rules repository on Glama.ai. No need to install anything! https://glama.ai/mcp/servers/timescale/rsigma These tools are provided: https://rsigma.io/guide/mcp-server/#mcp-server-tool-reference
glama.ai
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 07:57:10 UTC