Sigma Capability
Applies Sigma detections and correlation rules to normalized event streams. The documented syntax includes Sekoia-specific time modifiers, so rules may need adjustment when moved to another engine.
An independent tool index
for incident response teams
Detection and monitoring EU-developed
Cloud security operations product that ingests telemetry, applies detection rules, supports alert and case investigation, and runs automated playbooks.
By Sekoia · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Built by Sekoia.io SAS, a French security software company with its registered office in Rennes.
Sekoia hosts the core platform; on-premises playbook runners do not imply an on-premises Defend product. Reveal and Elevate are dependent add-ons. Full product license terms were not publicly verified.
identity / capabilities
Sekoia documentation identifies Defend as a core XDR product with log collection, detection, triage, case investigation and playbooks.
Read sourceorigin
The company describes its founding team and says they built a European cybersecurity software company and platform.
Read sourcecountry
The legal notice identifies Sekoia.io SAS and its registered office in Rennes, France.
Read sourcelicense / deployment
Official subscription documentation says Defend is licensed as a distinct paid product and identifies subscription tiers. It does not publish customer software rights or full product terms.
Read sourcemaintenance
Current documentation describes the active Defend product and current platform features; no ceased-support notice appears.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Applies Sigma detections and correlation rules to normalized event streams. The documented syntax includes Sekoia-specific time modifiers, so rules may need adjustment when moved to another engine.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection