Sigma rules converter

The Sigma rule converter converts correlation rules into a format that KUMA can parse and facilitates importing simple rules to be refined by an analyst.

To use the Sigma rule converter:

  1. Install the Sigma rule converter. The following installation options are available:
    • Installing the Sigma rule converter using docker + bash
    • Installing the Sigma rule converter in an environment that allows running docker images
    • Installing the Sigma rule converter using Python 3.10 or later

    After installation, log in to the web interface of the converter.

  2. Prepare a correlation rule.

    Sigma rule requirements

    Copy the correlation rule that you want to edit from KUMA to the 'rule' tab of the converter. Select the settings in the drop-down lists as necessary. Fix any errors if necessary.

  3. Copy the end result to KUMA if it is a query or a filter. If you want to use a rule in KUMA, you can import rules into KUMA one by one.
  4. Restart the correlator to apply the changes.

Your edited correlation is applied in the correlator.

In this section

Preparing a Sigma rule

Examples of supported Sigma rule conversions

Page top