Skip to main content

How to Add ATT&CK Tags to a Sigma Rule with AI

S
Written by Sergey Bayrachny

Use AI to map a Sigma rule to ATT&CK techniques and sub-techniques.

  1. Go to the Generate mode in Uncoder AI.

  2. Select Rule/Query as the input type.

  3. Paste your Sigma rule with no tags into the input panel. Uncoder AI will detect the language automatically. Ensure the detected language is correct or change it in the platform dropdown.

  4. Select Predict ATT&CK Tags as the output.

  5. Click Generate.

  6. The predicted technique and sub-technique IDs are added to the tags field of the Sigma rule.

Next Steps


After you've ensured that the Sigma rule fits your needs and preferences, you can:

  • Save it to a custom repository

  • Copy it to the clipboard and paste it into your system or download it as a file

  • Deploy it to a SIEM or push it to a Git repository

  • Translate it into a different language

  • Validate its syntax and structure

  • Get its short summary, full summary, or decision tree

  • Make custom modifications with AI

Did this answer your question?