❄️ Winter break is the perfect time to brush up on your Sigma rules! ❄️ With Sigma Specification 2.0 rules, #security teams can create vendor-agnostic detections without being limited by proprietary log formats. 🙌

So, security teams now have:
✅ New fields and modifiers that improve how security teams use the rules
✅ Correlation specifications to extend rules to more sophisticated detections
✅ Filters that reduce false positives
#JSON schema to allow automation

Learn more about the key changes in Sigma v.2.0 and supporting Sigma v2.0 mapped to MITRE ATT&CK framework.

https://graylog.org/post/sigma-specification-2-0-what-you-need-to-know/ #SigmaRules #CyberSecurity #SIEM #InfoSec

At #SIGMA project was split into two different projects a while back also accompanying a complete code rewrite-> the 2 projects are now #SIGMA and separately the #SIGMARULES

#hacklu2024

I have finally finished up the Sigma Room on TryHackMe. Super cool room that help me understand different IOCs (indicators of compromise). With it I have the write-up. Head over to my personal site or Medium to check it out:

#TryHackMe #SigmaRules #Sigma #SOCLevelTwoPath

https://haircutfish.com/posts/Sigma/

https://medium.com/@haircutfish/tryhackme-room-sigma-d70f9c606f93

TryHackMe Room — Sigma

TryHackMe Write-Up PowerShell CyberSecurity

Haircutfish
Introducing Sigma Specification v2.0 - Sigma_HQ

The SigmaHQ team is pleased to announce the latest update to the Sigma specification, the long awaited version 2.0 is now available for all Sigma users and creators. This release marks an important…

Sigma_HQ
SECOND BATCH DOWN WE'RE DOING THIS !!
#motivational #mindset #sigmarules #fyp #laundry

Threat Stack is where I started my security journey and I got into detection engineering there as well.

In light of the End-Of-Life announcement last year I decided to spearhead a project to open source our detection rules in the Sigma format and I'm proud to say that the project is complete! 

https://github.com/F5Networks/aip-to-sigma

I've been a huge fan of Sigma ever since I learned about it and my hope is that these rules will be of use to both customers and the detection community as whole...even if there is some overlap with the main Sigma repo 😅​

#SigmaRules #Sigma #DetectionEngineering #ThreatDetection #Infosec #OpenSource

GitHub - F5Networks/aip-to-sigma: AIP Rules Converted To The Sigma Format

AIP Rules Converted To The Sigma Format. Contribute to F5Networks/aip-to-sigma development by creating an account on GitHub.

GitHub
ShadowPad Trojan Detection: Redfly Hackers Apply a Nefarious RAT to Hit National Power Grid Organization in Asia - SOC Prime

Detect ShadowPad Trojan attacks with a set of Sigma rules in the SOC Prime Platform.

SOC Prime

Check out our new blog series explaining frequent mistakes made while writing #SigmaRules.

The kickoff writeup from our #ThreatHunting Lead
@acalarch covers unintentional escaped wildcards.
Stay tuned!
https://socprime.com/blog/frequent-sigma-mistakes-series/ #BlueTeam #DetectionEngineering #SOC #Sigma

Frequent SIGMA Mistakes Series - SOC Prime

Explore our article series on frequent SIGMA mistakes with the first one covering unintentional escaped wildcards to boost detection engineering skills.

SOC Prime
CVE-2023-38831 Detection: UAC-0057 Group Exploits a WinRAR Zero-Day to Spread a PicassoLoader Variant and CobaltStrike Beacon via Rabbit Algorithm - SOC Prime

Detect CVE-2023-38831 exploitation attempts in attacks by UAC-0057 spreading PicassoLoader & CobaltStrike Beacon with Sigma rules from SOC Prime Platform.

SOC Prime