Skip to content

Sigmacatch

Headless tool that captures real OS events: Windows Event Log API (winevt), EVTX files one-shot (cross-platform), and on Linux auditd, builtin syslog (central, authpriv and cron files), Sysmon-for-Linux (XML tail) and native eBPF probes. It matches them against SigmaHQ rules and outputs structured regression data ready for SigmaHQ PRs.

One binary named sigmacatch: the inputs are selected at compile time by cargo features and at runtime by the --evtx argument (one-shot EVTX), otherwise the live Winevt collector on Windows and every compiled, available Linux input in parallel.

The project is a single cargo workspace package (sigmacatch), plus a nested nightly-only eBPF probe crate (sigmacatch/ebpf); the main tree and each module's role are detailed in architecture.md.

Quick start

# Windows (default features):
cargo build --release -p sigmacatch
./target/release/sigmacatch            # Winevt live
# Linux (auditd + builtin syslog, no root):
cargo build --release -p sigmacatch --no-default-features --features auditd,builtin
./target/release/sigmacatch            # auditd + builtin syslog
# One-shot EVTX (cross-platform):
cargo build --release -p sigmacatch --no-default-features --features evtx
./target/release/sigmacatch --evtx /path/to/evtx/dir

The full feature matrix (sysmon, ebpf), the regressiondata-check validation binary, and the build/test commands are in build.md.

Documentation

A built version of this documentation is published to GitHub Pages: https://frack113.github.io/sigmacatch/

Français English
Architecture FR EN
Build FR EN
Configuration FR EN
CLI FR EN
Git FR EN
Output format FR EN
Regression data format FR EN

License

MIT