Sigma rule testing

Test Sigma on your own history before it pages anyone.

Most detection rules ship without ever seeing your data. In Huntbase, every Sigma rule is compiled onto OCSF, backtested on your history, run in shadow, and versioned like code.

01The lifecycle

From rule to watcher, with evidence at every stage.

  1. 01Write or importYour own Sigma, or SigmaHQ community rules that arrive switched off.
  2. 02CompileNative Sigma compiled onto OCSF fields, so one rule runs on every matching source.
  3. 03BacktestRun it over up to 90 days of your own history and see what it would have fired on.
  4. 04ShadowEvaluated on live data and recorded, but it only reaches the digest.
  5. 05Canary, then onStaged rollout once the evidence says it is ready. A rule that floods goes back to shadow.
Watcher · encoded PowerShell
title: Encoded PowerShell command line
logsource: { category: process_creation, product: windows }
detection:
 selection:
 Image|endswith: '\powershell.exe'
 CommandLine|contains: ' -enc '
 condition: selection
tags: [attack.t1059.001]
Compiles · bound toprocess_activityprocess.file.pathprocess.cmd_line
Backtest: 1d · 7d · 30d · 90dOffShadowCanaryOn

02What you get

Rules you can trust, and prove.

SigmaHQ, switched off

Enable the community rules and they land as watchers, off by default. Rules that cannot run on your data are grouped by reason, so gaps become a to-do list.

Honest backtests

Huntbase shows the fast approximate count and the rule's exact logic over a sample, and says so when the two disagree.

Versions with diffs

Every version keeps its author, note and diff. Restore any. Every firing names the version that fired.

Correlation rules

Sigma event count, value count and temporal ordering rules run on the same correlation engine.

Your other SIEMs

Convert any rule to Splunk SPL, Microsoft Sentinel KQL or Elastic ES|QL for data that stays where it is.

From hunt to watcher

Scout drafts a watcher from confirmed hunt findings. You backtest it and decide the rollout.

Questions

How do I test a Sigma rule before deploying it?

In Huntbase, backtest it over your own history for up to 90 days to see what it would have fired on, then run it in shadow mode, where it is evaluated on live data but only reaches the digest. Turn it on when the evidence says it is ready.

Can I import the SigmaHQ rules?

Yes. Enable the SigmaHQ community rules for your organisation and Huntbase fetches them for you. They arrive as watchers, switched off. Rules that cannot run on your data are grouped by reason, such as a field that is not mapped.

Does Huntbase convert Sigma to other query languages?

Huntbase compiles Sigma natively onto OCSF-normalised data. For data that stays in another SIEM, any rule can also be converted to Splunk SPL, Microsoft Sentinel KQL or Elastic ES|QL.

Are Sigma correlation rules supported?

Yes. Sigma correlation rules (event count, value count and temporal ordering) run on Huntbase's correlation engine.

Your rules.
Your history.
Your rollout.

Bring your Sigma, or start from SigmaHQ. Sign up and backtest on your own data, or book a demo.

  1. 01Sign up
  2. 02Run a guided hunt on the sample workspace, no connector needed
  3. 03Connect your own sources when you're ready