Skip to content
#

sigma-rules

Here are 26 public repositories matching this topic...

SigmaEye is a Windows process monitoring toolkit that integrates ETW and user-level monitoring with Sigma rules. It detects suspicious process behavior, LOLBins usage, and potential threats in real-time. Features include dual monitoring, DLL injection tracking, and customizable detection rules. Requires admin privileges for ETW monitoring.

  • Updated Feb 22, 2025
  • Python

Improve this page

Add a description, image, and links to the sigma-rules topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the sigma-rules topic, visit your repo's landing page and select "manage topics."

Learn more