Straight answer

Sigma is an open, generic format for writing a detection rule once and converting it to different query languages. Several tools on this site write rules in each platform's native query language instead, or publish their own open formats. For a buyer the question is portability: can you read, export and reuse the rules a tool writes?

What Sigma is

Sigma describes itself as a "generic and open signature format" for log events. A rule is written once, in a readable structure, and converted by tools such as Sigma CLI and pySigma into the query language of a specific SIEM or data platform. The SigmaHQ repository holds more than 3,000 rules, published under the Detection Rule License 1.1.

The rule set moves steadily. SigmaHQ published release r2026-01-01 on 29 January 2026 with 33 new rules focused on EDR evasion and vulnerable driver abuse, r2026-04-01 on 28 April with 54 new rules and more than 60 improved, focused on NPM compromises and credential access, and r2026-07-01 on 9 July with 20 new rules and more than 80 updated, including supply-chain attack coverage.

Two ways a tool can produce a rule

A tool can write a rule in an intermediate format such as Sigma and convert it for each platform, or it can write the query directly in each platform's native query language. Both reach the same place: a query that runs where the data lives. The difference shows up later, when you want to review, move or reuse the rule.

How the six tools describe their rules

  • Mars Security states that it writes queries in the native query language of each source and maps rules to ATT&CK. Its public pages do not describe version history or export.
  • Nebulock lets rules be edited via chat or direct SQL, exports them to GitHub and keeps an immutable version history with compare and revert. Its Agentic Detection Engineering Framework is open source under the MIT license.
  • Vega keeps detections in source control, where every change has a diff, an author and an approver. In August 2026 it released Detection Skills, an open specification built on the Agent Skills format, with more than 50 skills.
  • Anvilogic describes detection-as-code with version control and thousands of MITRE-mapped detections.
  • Cotool says it is compatible with existing detection-as-code infrastructure and adds version control for its agents.
  • Artemis Security writes and tunes detections automatically; we found no description of a rule format, versioning or export.

We did not find Sigma import or export mentioned on the pages we reviewed for any of the six. If your team keeps rules in Sigma, ask.

Why portability matters for this site's question

The buyer question here is about hunting and detecting on the data you already have. The same logic applies to rules: a team that already maintains detections wants the new ones in a form it can read, review and keep, whichever tool wrote them. Portability is part of what our rule lifecycle row looks at, alongside testing, version history and rollback. It carries 7% of the weighted figure; teams for whom it matters more can raise it in the calculator.

Where open formats and native queries meet

The two approaches are not exclusive. A team can keep its own rules in Sigma, convert them with pySigma for each platform, and still let a tool write native queries for new intelligence. What matters is that both sets of rules end up somewhere the team can see and manage them. Ask whether the tool can read rules you already run on your platforms, so its coverage view and tuning include them, and whether rules it writes can live alongside yours in the same repository.

Four questions about rule formats

  1. In what format does the tool store the rules it writes, and can we read them outside the product?
  2. Can we export rules to our own repository, and does the export keep the version history?
  3. Can the tool import our existing rules, including Sigma rules, and convert them for our platforms?
  4. If we stop using the tool, which rules keep running on our platforms, and in what form?