Detection automation
YARA to Sigma
Translate malware intelligence into portable SIEM and EDR detections.
- Focus
- Detection automation
- Updated
- June 2026
- Stack
- Python, YARA, Sigma, Flask, Docker
Overview
Built for operational clarity.
A modular web and CLI engine that converts YARA rules to Sigma and native queries with IOC classification, ATT&CK tagging, and configurable pipelines.
This project reflects a product-oriented approach to security engineering: start with a recurring operational problem, reduce unnecessary steps, and make the result usable across real environments.
What it delivers
017 output backends
02Web UI and CLI
03IOC classification
04Configurable pipelines
Engineering approach
Portable, inspectable, and ready to operate.
The implementation emphasizes explicit workflows, deployable packaging, and technology choices that remain understandable to the teams running them.
PythonYARASigmaFlaskDocker