Sigmaforge
Sharleen · Team Sharleen-solo
Submitted to Defensive Acceleration Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
SigmaForge is an LLM-assisted detection engineering assistant that turns unstructured threat intel and example logs into high-quality Sigma detection rules and real, deployable SIEM queries. Analysts can paste a natural-language description (or log snippets), and SigmaForge generates a Sigma rule, validates it using the official pySigma tooling, and compiles it into Splunk and Elasticsearch/Lucene queries. The tool also surfaces rule-quality warnings (e.g. missing ATT&CK tags, noisy wildcards) and provides a quick log sanity check, helping understaffed SOC teams move from “we know about this attack” to “we are detecting this attack” in minutes instead of hours.
Reviews
No public critique yet.
Cite this project
@misc{sharleen2025sigmaforge,
title = {{Sigmaforge}},
author = {Sharleen},
year = {2025},
month = nov,
note = {Submitted to Defensive Acceleration Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/sigmaforge-pyf6}},
url = {https://apartresearch.com/sprints/projects/sigmaforge-pyf6}
}More from Defensive Acceleration Hackathon
- View project: Neops - DevSecOps for the AI era
Neops - DevSecOps for the AI era
Broad Bros
NEOps is a CLI-based tool that embeds AI safety into your product lifecycle from day one. While development teams routinely build cybersecurity checks, AI-safety often comes later—or not at all. NEOps fills that gap by …
- View project: Assisted Audit of Solana Programs
Assisted Audit of Solana Programs
GLAM
Multi-agent solution that assists in auditing Solana programs, allows to consolidate audit findings into a knowledge base, and can integrate into CI/CD pipelines to prevent security regressions.
- View project: Mechanistic Watchdog
Mechanistic Watchdog
SL5
Mechanistic Watchdog is a mechanistic-interpretability-based “cognitive kill switch” for language models. Instead of only filtering final text, we monitor a model’s internal activations in real time and learn linear …