DEV Community

Bijan
Bijan

Posted on AI-assisted

I Gave My SOC Experience to AI. It Gave Me Sigma Rules.

After spending time in a SOC, you start noticing patterns.

Different alerts. Different machines. Different incidents.

But eventually, you realize that a lot of the attacks you're seeing aren't completely new.

The same techniques keep coming back.

An Office application spawning something it shouldn't.

PowerShell being used in suspicious ways.

Security controls being tampered with.

Software quietly abusing system resources.

You see these things, investigate them, stop them, and move on to the next alert.

I started wondering:

What if I took some of the attack scenarios and TTPs I've actually encountered and turned them into reusable detection rules?

That's how I started working on SigmaVault.

I provided AI with some of the attack scenarios and TTPs I'd encountered and stopped during my SOC work, then asked it to generate Sigma rules around those scenarios.

The goal wasn't to blindly generate a pile of rules and call it detection engineering.

I wanted to experiment with something more useful:

Can practical SOC experience be turned into structured, reusable detections?

For example, instead of keeping an attack pattern in my head as:

"I've seen this behavior before."

I can turn it into something closer to:

Attack behavior
      ↓
Relevant telemetry
      ↓
Detection logic
      ↓
Sigma rule
      ↓
SIEM / detection pipeline
Enter fullscreen mode Exit fullscreen mode

There is one important disclaimer, though.

The rules aren't tested yet.

So I'm treating SigmaVault as a work in progress rather than claiming these are production-ready detections.

The next step is testing and tuning them against real telemetry, looking at false positives, and figuring out where the generated logic actually holds up.

And I'm not planning to stop with the initial scenarios.

I'd like to expand the project with more attack techniques and eventually add Linux-focused detections as well.

That's what makes this project interesting to me.

It's not really about getting AI to write YAML.

It's about taking things I've encountered in the SOC, turning them into detection hypotheses, and then testing whether those hypotheses can become useful detection logic.

Maybe some rules will be wrong.

Maybe some will be noisy.

Maybe some will actually turn out to be useful.

That's the part I want to find out.

SigmaVault:
https://github.com/bijan53c/SigmaVault

If you spot something that could be improved, or have a detection scenario worth adding, let me know.

Hope it helps someone else working on their own detection engineering journey.

Top comments (0)