MISP
Threat intelligence · Luxembourg
Read the tool profileDocumented support
Stores Sigma rules and their references in a dedicated Sigma object template. This is rule storage and exchange, not execution of Sigma detections.
An independent tool index
for incident response teams
Documented work with Sigma detection rules. The profile explains whether a tool writes, imports, converts or applies rules.
Filter these toolsEach entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.
Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.
6 tools with documented Sigma support.
Threat intelligence · Luxembourg
Read the tool profileStores Sigma rules and their references in a dedicated Sigma object template. This is rule storage and exchange, not execution of Sigma detections.
Detection and monitoring · Belgium
Read the tool profileUses pySigma to validate and convert Sigma rules with platform and log-source transformations, then search or deploy them to configured platforms.
Detection and monitoring · France
Read the tool profileBehavioral detection evaluates endpoint events with configurable Sigma rules. The documented OpenCTI connector can forward Sigma rules, but does not parse or validate them.
Detection and monitoring · France
Read the tool profileApplies Sigma detections and correlation rules to normalized event streams. The documented syntax includes Sekoia-specific time modifiers, so rules may need adjustment when moved to another engine.
Feed automation · Germany
Read the tool profileIts sigma operator evaluates Sigma v2.1 detection rules and global filters over structured events. Correlation rules are explicitly unsupported.
Malware analysis · Germany
Read the tool profileApplies Sigma rules to Windows Eventlogs, disk log files and selected internal objects. Releases before THOR 10.7 require Sigma scanning to be explicitly enabled.
A missing tool may support this feature without having been checked in this research pass.
Send a source or correction