اسیگما رولز برای مبتدیان: نوشتن قوانین تشخیص Blue Team
آموزش گامبهگام نوشتن Sigma rules برای تشخیص threat در SIEM. شامل template، مثالهای واقعی، و استراتژیهای false positive reduction.
# اسیگما رولز برای مبتدیان: نوشتن قوانین تشخیص Blue Team
**Sigma** یک فرمت استاندارد است برای نوشتن قوانین تشخیص لاگ. یک قانون اسیگما میتواند به SPL (Splunk)،KQL (Microsoft Sentinel)، و YARA تبدیل شود. این به Detection Engineers اجازه میدهد تا یک بار قانون بنویسند و در هر SIEM اجرا کنند.
## قالب پایه (Template)
```yaml
title: Suspicious PowerShell Execution
id: d8e7c6a5-1234-5678-9abc-def012345678
status: experimental
description: Detects suspicious PowerShell execution patterns
references:
- https://attack.mitre.org/techniques/T1059/
author: Alireza Abedi
date: 2026/08/23
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
service: sysmon
detection:
selection_img:
Image|endswith: '\powershell.exe'
selection_cli:
CommandLine|contains:
- '-enc '
- '-EncodedCommand'
- 'DownloadString'
condition: selection_img and selection_cli
falsepositives:
- Legitimate PowerShell scripts
level: high
```
## گام 1: Logsource تعریف کنید
Logsource به SIEM میگوید چه لاگهایی را باید جستجو کنید:
| فیلد | مثال |
|------|------|
| product | windows, linux, network |
| service | sysmon, security, dns |
| category | process_creation, file_event |
## گام 2: Detection بنویسید
قوانین کلیدی نوشتن:
| عملگر | توضیح | مثال |
|-------|-------|------|
| `contains` | شامل مقدار باشد | `CommandLine|contains: 'whoami'` |
| `endswith` | با مقدار خاتمه یابد | `Image|endswith: '\cmd.exe'` |
| `startswith` | با مقدار شروع شود | `Image|startswith: 'C:\Windows'` |
| `all` | همه مقادیر true باشند | `CommandLine|all` |
| `re` | عبارت منظم | `Image|re: 'cmd\.exe$'` |
## گام 3: Condition بنویسید
| Pattern | معنی |
|---------|------|
| `selection` | یک گروه selection برقرار است |
| `selection1 and not selection2` | selection1 AND NOT selection2 |
| `1 of selection*` | هر یک از selections |
| `all of selection*` | همه selections |
## مثال واقعی: تشخیص T1059.001 (PowerShell)
این قانون PowerShell با پارامترهای مخرب را تشخیص میدهد:
```yaml
logsource:
product: windows
service: sysmon
detection:
selection_ps:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
selection_flags:
CommandLine|contains|all:
- '-e'
- '-'
condition: selection_ps and not selection_flags
```
## گام 4: False Positive Reduction
1. **Legitimate paths**: `Image|contains: '\Program Files\'` → استثنا بزنید
2. **Known scripts**: `CommandLine|contains: 'install.ps1'` → سفید لیست کنید
3. **User context**: `User|contains: 'svc_'` → فیلتر کنید
## گام 5: اسکوی سازمان خودتان
Sigma را برای Splunk تبدیل کنید:
```bash
# از ابزار Sigmac استفاده کنید
python sigmac -t splunk -c splunk-winlogbeat sigma-rule.yml
```
## نکات پیشرفته
- **Field mapping**: برای هر لاگسورس، فیلدهای Sigma را به فیلدهای actual SIEM ربط دهید
- **Threshold**: از `condition: X | count() by EventID > 5` برای تشخیص burst استفاده کنید
- **Status**: از `experimental` برای تست و `stable` برای production استفاده کنید
- **Tags**: حتماً MITRE ATT&CK tags اضافه کنید (`attack.t1059.001`)
## Resources منابع
- [Sigma GitHub](https://github.com/SigmaHQ/sigma) — 3000+ قانون رایگان
- [Sigma Wiki](https://github.com/SigmaHQ/sigma/wiki) — مستندات کامل
- [Sigmaize](https://sigmaize.io/) — UI بصری برای نوشتن قوانین
- [Unify](https://unify.oneflorisoft.dev/) — تست و اعتبارسنجی قوانین
---
*بهروزرسانی شده: اوگست ۲۰۲۵ | نویسنده: آریزرا عبادی — تیم امنیتی Blue Team*