droid
is a PySigma wrapper allowing an easy adoption of Sigma and helps enabling Detection-As-Code. The ultimate goal of droid
is to consume a repository Sigma rules and deploy them on one or multiple platform (SIEM/EDR).
The tool also supports plain SIEM/EDR search queries.
Key features are:
- Validate the syntax of Sigma rules
- Convert them by applying a set of transforms per log source and platform
- Search in logs and report on findings
- Test the rules by leveraging Atomic Red Team™ (work in progress)
- Deploy them with any compatible SIEM and EDR (.e.g. Splunk, Microsoft Sentinel)
Licensed under the EUPL.