Welcome to RSigma's documentation!

Welcome to RSigma’s documentation!

RSigma is a Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, and MCP and LSP servers. It builds on open industry standards throughout: Sigma for detection rules, OpenTelemetry for log ingestion and detection export, and STIX and TAXII for threat intelligence.

Install RSigma

Install with a signed binary archive, Docker, or Cargo.

Installation steps

Quickstart

Write a rule, evaluate it, run the daemon, and convert to SQL.

Getting started

Core concepts

Sigma rules, processing pipelines, the eval/daemon split, and the noun-led CLI.

Core concepts

Detection engineering loop

Author, test, deploy, detect, alert, measure, and hunt: one map of the full lifecycle.

The loop

CLI Reference

Per-subcommand reference for engine, rule, backend, pipeline, hunt, taxii, mcp, and config.

CLI Reference

Rule conversion

Generate PostgreSQL, LynxDB, or Fibratus queries natively, or Splunk, Elasticsearch, Kusto, and other pySigma targets through sigma-cli.

Rule conversion

Streaming detection

Run the daemon with NATS, HTTP, or OTLP input. Hot-reload, metrics, state.

Streaming detection

Why RSigma

RSigma pySigma sigma_engine sigma-rust
Language Rust Python Rust Rust
Runtime evaluation Yes (streaming + stateful) No (converter only) Yes (stateless) Yes (stateless)
Correlation rules All 8 types Partial No No
Filter rules Yes Yes No No
Conversion backends PostgreSQL, LynxDB, Fibratus natively; pySigma backends through sigma-cli 30+ No No
Streaming daemon Yes (NATS, HTTP, OTLP) No No No
Dynamic pipelines Yes (HTTP, file, command, NATS) Yes (HTTP, file, command) No No
Built-in linter 90 rules, auto-fix Limited No No
LSP server Yes No No No
Single binary Yes (multi-arch, signed) No (requires Python) Library only Library only
License MIT LGPL-3.0 AGPL-3.0 MIT

RSigma combines pySigma-style conversion with a streaming evaluator in one self-contained binary.

Outlet Quote
DEW #149 (March 2026) “RSigma is essentially a SIEM. Building a tool like RSigma is challenging because the Sigma specification has evolved into a robust domain-specific language over the years.”
tl;dr sec #320 (March 2026) “Accurately evaluating the full spectrum of what Sigma rules can express is quite complex. It’s pretty neat to read about how RSigma handles all of these conditional expressions, correlating across rules, etc.”
BlackNoise (March 2026) “Defensive teams can pipe logs through CLI commands, apply field-mapping pipelines, and chain correlations for multi-stage attack detection.”
DEW #154 (April 2026) “RSigma is not a SIEM, but it’s an impressive feat to build a self-contained Rust binary that operates much like one. For teams doing pre-SIEM rule validation or forensics, it’s a solid plug-and-play option.”
DEW #157 (May 2026) “Instead of hardcoding IOC values in rule YAML, you declare external sources in the pipeline config, and RSigma fetches and injects them at evaluation time.”
This Week in Rust 663 (August 2026) Featured the RSigma v0.20.0 release and The State of RSigma, and Part Two: The Loop.
Rust Bytes #139 (October 2026) Featured RSigma in the Project Spotlight.

Built with RSigma

Project Role
detection.studio Browser-based Sigma playground with real-time evaluation via RSigma compiled to WebAssembly
Garmr Self-hosted application-audit and insider-risk platform using RSigma for per-event Sigma detection
LocalObserve Local-first Linux security observability stack using RSigma for edge Sigma detection and webhook alerting
Rustinel Cross-platform endpoint detection engine with RSigma as the only Sigma backend for live telemetry
sagan2sigma Converts Sagan rules to Sigma and verifies them with RSigma
Sheut Local-first cyber threat intelligence workbench using RSigma for STIX 2.1 validation and interchange
Sigmacatch Captures live Windows Event Log events, matches them with RSigma, and writes SigmaHQ-ready regression data

Read the deep dives

An article series on building RSigma and using it in production:

# Article Topic
1 Pattern Detection and Correlation in JSON Logs Forensic investigation of a Trivy supply-chain compromise
2 Streaming Logs to RSigma for Real-Time Detection Okta cross-tenant impersonation via the daemon and NATS JetStream
3 Building a Detection Layer on PostgreSQL with Sigma Rules Five PostgreSQL output formats and TimescaleDB continuous aggregates
4 Security Observability with RSigma and the LGTM Stack Pairing RSigma with Loki, Mimir, and Grafana
5 Wiring Live Threat Intel into Sigma Detection with Dynamic Pipelines Dynamic pipelines: HTTP, file, command, and NATS sources
6 Cloud Detection at Scale on a Laptop Running cloud-scale detection locally with RSigma
7 The State of RSigma A tour of everything RSigma does today and where it is headed
8 Detection-as-Code in One GitHub Action with RSigma Gating a Sigma rule repository in CI with lint, validate, fields-drift, backtest, and ATT&CK coverage
9 The State of RSigma, Part Two: The Loop One detection through the full lifecycle: author, test, deploy, detect, alert and triage, measure, and hunt

At a glance

  • Latest release: v0.24.0 (MIT licensed; 9 crates in the workspace).
  • MSRV: Rust 1.96.0, edition 2024.
  • Cross-platform binaries: Linux, macOS, Windows on amd64 and arm64.
  • Container image: ghcr.io/timescale/rsigma:latest (multi-arch, cosign-signed, SBOM, SLSA Build L3 provenance).
  • Benchmarks: detection and correlation throughput numbers live on the benchmarks page.

Versions

This site is published from the main branch, so it can describe changes that are not in a release yet. Tags show when something became available, and each tag links to its release notes:

  • A tag below a page title gives the release that added the command or feature, for example Added in v0.22.0 on a page added in v0.22.0. Every CLI command page has one; commands that predate v0.12.0 show v0.12.0, the release that moved the CLI to command groups and gave them their current names. Guide and reference pages without a tag describe features available since v0.12.0.
  • A tag on a section, flag, config key, or table row marks an addition made to an existing page from v0.22.0 onward. For older changes within a page, see the release notes.
  • Added in v0.24.0 marks a change merged to main that is not in a release yet.

Run rsigma --version to see which release you have.