Sigma Capability
Uses pySigma to validate and convert Sigma rules with platform and log-source transformations, then search or deploy them to configured platforms.
An independent tool index
for incident response teams
Detection and monitoring CSIRT-led
Validates and transforms Sigma detection rules, then searches or deploys them across compatible SIEM and EDR environments through a command-line workflow.
By CERT-EU · Belgium
Primary sources connect this project to an EU CSIRT as developer or lead.
The project is published by CERT-EU, the EU institutions' computer emergency response team based in Brussels, Belgium.
The README marks Atomic Red Team testing as work in progress. Country denotes CERT-EU's Brussels base, not a claim that every contributor works in Belgium.
identity / capabilities
README defines droid as a pySigma wrapper for detection-as-code and describes validation, transformation, searching and deployment to supported SIEM/EDR systems; Atomic testing is work in progress.
Read sourcedeployment
Official getting-started documentation installs detect-droid with pip and configures a local command-line environment.
Read sourceorigin / country
CERT-EU describes itself as the interinstitutional cybersecurity service and computer emergency response team for EU institutions.
Read sourcecountry
Official contact page gives a Brussels, Belgium physical address; this is the institutional base of the publisher.
Read sourcelicense
Actual project LICENSE contains European Union Public Licence version 1.2 text.
Read sourcemaintenance
Upstream default-branch Atom feed records a commit on 2026-09-29; branch activity is not a support guarantee.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Uses pySigma to validate and convert Sigma rules with platform and log-source transformations, then search or deploy them to configured platforms.
Searches and deploys rules as Splunk saved searches using a configured Splunk platform and credentials. Sigma conversion requires the separately installed Splunk backend.
Searches and exports Elastic Security rules through configured Elasticsearch and Kibana endpoints. Supports EQL and ES|QL; the guide limits Sigma correlation rules to ES|QL.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection