Sigma Rules and Detection-as-Code
Sigma is a vendor-neutral, open specification for writing threat detection rules in a format that can be converted into the query language of any Security Information and Event Management (SIEM) platform.
This article requires CONFIDENTIAL clearance or higher.
What you need
Create a free Nexus ID to access CDA proprietary content including PDM domain explainers, methodology deep-dives, and reconnaissance mission briefings.
Create Nexus ID (Free)Sign in with Google, Microsoft, GitHub, or LinkedIn