IBM Cyber Security Center of Excellence (CCoE)

Beer Sheva

in Collaboration with Ben-Gurion University of the Negev

May 22, 2023 – SIGMA rules optimized for QRadar users released by IBM Security

IBM’s new pySigma QRadar AQL backend was published.

By the end of 2023, SIGMA’s Sigmac project is to be replaced by pySigma. In order to help existing QRadar users continue consuming Sigma rules, CCoE created a pySigma QRadar AQL backend module and integrated it with pySigma. The new module allows content to be optimized for QRadar and offers the conversion of Sigma rules to QRadar queries in Ariel Query Language (AQL) with performance optimization.
Read the blog post here.