Importing Sigma security rules

The Sigma format is a standard unified language for describing log-based incident detection rules. In particular, Sigma rules can be used to create and share standardized detection rules that can be used regardless of the SIEM or system.

They are written in a text file in YAML format and sent to SES Evolution via its public API by a SIEM or a security administrator. For more information, see the Sigma Documentation.

Stormshield has developed two import scripts used to send Sigma rules to the SES Evolution API, convert them to SES Evolution rules, and deploy them to the agents.

If you want to use API requests directly without the help of Stormshield scripts, see Enabling and managing SES Evolution's public API and the API documentation.

You can enable Sigma security rules via advanced protection: Sigma advanced protection.