Detection and monitoring CSIRT-led

droid

Validates and transforms Sigma detection rules, then searches or deploys them across compatible SIEM and EDR environments through a command-line workflow.

By CERT-EU · Belgium

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CERT-EU
Recorded country
Belgium
Product model
Open source
Deployment
Desktop/CLI
Software license
EUPL-1.2
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The project is published by CERT-EU, the EU institutions' computer emergency response team based in Brussels, Belgium.

Reported capabilities

  • Sigma detection-as-code workflow
  • Rule validation and transformation
  • SIEM and EDR query or deployment

Scope and limits

The README marks Atomic Red Team testing as work in progress. Country denotes CERT-EU's Brussels base, not a claim that every contributor works in Belgium.

Inspect the research evidence 6 source observations
  1. identity / capabilities

    README defines droid as a pySigma wrapper for detection-as-code and describes validation, transformation, searching and deployment to supported SIEM/EDR systems; Atomic testing is work in progress.

    Read source
  2. deployment

    Official getting-started documentation installs detect-droid with pip and configures a local command-line environment.

    Read source
  3. origin / country

    CERT-EU describes itself as the interinstitutional cybersecurity service and computer emergency response team for EU institutions.

    Read source
  4. country

    Official contact page gives a Brussels, Belgium physical address; this is the institutional base of the publisher.

    Read source
  5. license

    Actual project LICENSE contains European Union Public Licence version 1.2 text.

    Read source
  6. maintenance

    Upstream default-branch Atom feed records a commit on 2026-09-29; branch activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

Sigma Capability

Uses pySigma to validate and convert Sigma rules with platform and log-source transformations, then search or deploy them to configured platforms.

Splunk Integration

Searches and deploys rules as Splunk saved searches using a configured Splunk platform and credentials. Sigma conversion requires the separately installed Splunk backend.

Elastic Integration

Searches and exports Elastic Security rules through configured Elasticsearch and Kibana endpoints. Supports EQL and ES|QL; the guide limits Sigma correlation rules to ES|QL.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection