// Detection Engineering

Sigma Rule Builder

Visual rule editor · Real-time conversion to Splunk SPL, Elastic KQL, Microsoft Sentinel KQL · 8 templates

Build Sigma detection rules with a visual form editor and watch them convert live to Splunk SPL, Elastic KQL, and Microsoft Sentinel KQL as you type — no need to hand-write YAML or learn three separate query languages. Start from one of 8 ready-made templates covering failed logons, PowerShell obfuscation, process injection, lateral RDP movement, scheduled task abuse, DNS tunneling, shadow copy deletion, and LOLBin execution, then adjust the fields for your own environment. Built for detection engineers and SOC teams who need to ship a working, portable rule to their SIEM quickly rather than debugging YAML syntax by hand.

Templates:
Condition
Blocks: 0
Fields: 0
Level: medium
Index: wineventlog
Sigma YAML — Generic Detection Format
Splunk SPL — Search Processing Language
Elastic KQL — Kibana Query Language
Microsoft Sentinel KQL — Kusto Query Language