Nov 23, 2025
Sigmaforge
Sharleen
SigmaForge is an LLM-assisted detection engineering assistant that turns unstructured threat intel and example logs into high-quality Sigma detection rules and real, deployable SIEM queries. Analysts can paste a natural-language description (or log snippets), and SigmaForge generates a Sigma rule, validates it using the official pySigma tooling, and compiles it into Splunk and Elasticsearch/Lucene queries. The tool also surfaces rule-quality warnings (e.g. missing ATT&CK tags, noisy wildcards) and provides a quick log sanity check, helping understaffed SOC teams move from “we know about this attack” to “we are detecting this attack” in minutes instead of hours.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Sigmaforge
},
author={
Sharleen
},
date={
11/23/25
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


