Back to selected work

Detection automation

YARA to Sigma

Translate malware intelligence into portable SIEM and EDR detections.

Focus
Detection automation
Updated
June 2026
Stack
Python, YARA, Sigma, Flask, Docker

Overview

Built for operational clarity.

A modular web and CLI engine that converts YARA rules to Sigma and native queries with IOC classification, ATT&CK tagging, and configurable pipelines.

This project reflects a product-oriented approach to security engineering: start with a recurring operational problem, reduce unnecessary steps, and make the result usable across real environments.

What it delivers

017 output backends
02Web UI and CLI
03IOC classification
04Configurable pipelines

Engineering approach

Portable, inspectable, and ready to operate.

The implementation emphasizes explicit workflows, deployable packaging, and technology choices that remain understandable to the teams running them.

PythonYARASigmaFlaskDocker
Continue exploring View all projects