MOAR Stack · Well-connected
Sigma detections.
Vendor-neutral detection-as-code so the logic travels across engines. Atomic detections travel cleanly; correlation-heavy logic is not yet at parity.
Well-connected component · 3 essays
Listed from the front door down to the measured evidence. Start here marks the entry essay. The reading-level tag says whether you are reading the frame (Orientation), the argument (Depth), or a first-party finding (Evidence). The durability tag flags durable architecture versus an Evidence-pinned result tied to a version or price.
- Start here OrientationEvidence-pinned
Sigma and detection portability.
The fourth foundational standard. Why Sigma sits alongside Iceberg, Arrow, and OCSF as the standards that decouple security data from any single vendor's analytics engine.
Read →
- DepthEvidence-pinned
Why Sigma won the detection-sharing decade.
A decade of attempts to share security use cases — Sysmon configs, hunt notebooks, MITRE CAR, Atomic Red Team, Sigma — and only some endured. The difference wasn't quality; the best Sysmon config froze in 2021. Five structural properties predict what lasts, and Sigma has them by construction.
Read →
- EvidenceEvidence-pinned
Sigma 2.0 correlations and the pySigma backend reality.
Sigma 2.0 added correlation semantics that the backends haven't fully caught up to. Which backends ship the new constructs, which don't, and where that breaks in production.
Read →
Capability Matrix
The Matrix scores detection portability and backend conversion fidelity.
See the Capability Matrix →