Skip to main content

Sigma

Download With Dependencies

This pack contains all needed objects to import and manage Sigma rules within Cortex TIM

Sigma

Overview

The Sigma Detection Rules content pack provides an integration with Sigma, a generic and open signature format for SIEM systems. This content pack enables you to create, manage, and utilize Sigma detection rules within Cortex TIM. Sigma rules allow you to describe relevant log events in a straightforward and universal format, which can be easily converted to SIEM-specific queries.

What does this pack do?

This new pack enables you to import Sigma rules either via a string or by a file into the Cortex TIM. Once in the system you can use the built-in scripts to convert the newly added rules into the format of your choice and use it to query 3rd party security products.

Content delivered with the content pack

  • An additional Cortex indicator type called "Sigma Rule".
  • All the relevant fields needed to store the data of the "Sigma Rule" indicator.
  • A new layout for the newly added indicator type.
  • Utility scripts needed to import Sigma rules and export them in the user chosen format.
Additional Information

For more information about Sigma and its uses, visit Sigma HQ.

Sigma

Overview

The Sigma Detection Rules content pack provides an integration with Sigma, a generic and open signature format for SIEM systems. This content pack enables you to create, manage, and utilize Sigma detection rules within Cortex TIM. Sigma rules allow you to describe relevant log events in a straightforward and universal format, which can be easily converted to SIEM-specific queries.

What does this pack do?

This new pack enables you to import Sigma rules either via a string or by a file into the Cortex TIM. Once in the system you can use the built-in scripts to convert the newly added rules into the format of your choice and use it to query 3rd party security products.

Content delivered with the content pack

  • An additional Cortex indicator type called "Sigma Rule".
  • All the relevant fields needed to store the data of the "Sigma Rule" indicator.
  • A new layout for the newly added indicator type.
  • Utility scripts needed to import Sigma rules and export them in the user chosen format.
Additional Information

For more information about Sigma and its uses, visit Sigma HQ.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedSeptember 29, 2024
Last ReleaseMarch 22, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
By downloading or using Marketplace content, you agree to the applicable Terms of Use and End User License Agreement. Third-party content is provided by its publisher, and Palo Alto Networks does not warrant, endorse, support, or assume responsibility for content not expressly identified as owned by Palo Alto Networks.