$ -weight: 500;">git clone https://github.com/TiltedLunar123/SIEMForge.-weight: 500;">git
cd SIEMForge
-weight: 500;">pip -weight: 500;">install pyyaml
-weight: 500;">git clone https://github.com/TiltedLunar123/SIEMForge.-weight: 500;">git
cd SIEMForge
-weight: 500;">pip -weight: 500;">install pyyaml
-weight: 500;">git clone https://github.com/TiltedLunar123/SIEMForge.-weight: 500;">git
cd SIEMForge
-weight: 500;">pip -weight: 500;">install pyyaml
# See what's in the toolkit
python siemforge.py # Convert all rules to Splunk SPL
python siemforge.py --convert splunk # Convert a single rule to Kibana KQL
python siemforge.py --convert kibana --convert-rule lsass_credential_dump.yml # View MITRE ATT&CK coverage
python siemforge.py --mitre # Export everything as a packaged bundle
python siemforge.py --export-all
# See what's in the toolkit
python siemforge.py # Convert all rules to Splunk SPL
python siemforge.py --convert splunk # Convert a single rule to Kibana KQL
python siemforge.py --convert kibana --convert-rule lsass_credential_dump.yml # View MITRE ATT&CK coverage
python siemforge.py --mitre # Export everything as a packaged bundle
python siemforge.py --export-all
# See what's in the toolkit
python siemforge.py # Convert all rules to Splunk SPL
python siemforge.py --convert splunk # Convert a single rule to Kibana KQL
python siemforge.py --convert kibana --convert-rule lsass_credential_dump.yml # View MITRE ATT&CK coverage
python siemforge.py --mitre # Export everything as a packaged bundle
python siemforge.py --export-all
--export-all - Sigma rule conversion — translates detection rules to Splunk SPL, Elasticsearch Lucene, or Kibana KQL without any external dependencies (no sigmac needed)
- 10 pre-built detection rules covering credential dumping (T1003.001), process injection (T1055.003), lateral movement via PsExec (T1021.002), suspicious PowerShell (T1059.001), SSH brute-force (T1110.001), and more
- Tuned Sysmon configuration for Windows event monitoring
- Wazuh custom rules with agent config snippets
- MITRE ATT&CK mapping across all rules
- One-command export of the complete detection package