Stories by Mostafa Moradian on Medium · Feb 24, 2026
Pattern Detection and Correlation in JSON Logs
0Sign in to vote or save
This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.
Introducing RSigma: a Rust toolkit for evaluating Sigma detection rules against JSON events without a SIEM high-level detection pipeline You have a stream of JSON logs. Maybe it’s an NDJSON export from an incident investigation, a dump of Okta audit events, CloudTrail records from a compromised AWS account, or simply the output of a service you’re debugging. You want to find suspicious patterns,…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.