Sigma support, in detail.

Documented work with Sigma detection rules. The profile explains whether a tool writes, imports, converts or applies rules.

Filter these tools

Check the actual function

Each entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.

Before you connect it

Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.

6 tools with documented Sigma support.

MISP

Threat intelligence · Luxembourg

Read the tool profile

Documented support

Stores Sigma rules and their references in a dedicated Sigma object template. This is rule storage and exchange, not execution of Sigma detections.

droid

Detection and monitoring · Belgium

Read the tool profile

Documented support

Uses pySigma to validate and convert Sigma rules with platform and log-source transformations, then search or deploy them to configured platforms.

Sekoia Defend

Detection and monitoring · France

Read the tool profile

Documented support

Applies Sigma detections and correlation rules to normalized event streams. The documented syntax includes Sekoia-specific time modifiers, so rules may need adjustment when moved to another engine.

A missing tool may support this feature without having been checked in this research pass.

Send a source or correction