XQL

Sigma to Cortex XDR

Paste a Sigma rule, get a Cortex XQL query over the xdr_data dataset. Free, no sign-up.

  1. Paste the ruleYAML in
  2. Pick your SIEMPalo Alto Cortex XDR · XQL
  3. Read the reportQuery, field map, gaps
certutil
Tab indents · Shift+Tab outdents · Esc then Tab leaves the fieldValid Sigmaprocess_creation · windows29 lines · 968 B
Splunk logo An information technology company based in California, United States Splunk2
Microsoft3
Elastic3
CrowdStrike1
SentinelOne1
Palo Alto Networks1
Carbon BlackCarbon Black2
Google Security OperationsGoogle1
IBM1
Sumo Logic1
Rapid71
Graylog1
OpenSearch2
Grafana1
DFIR2

No query was emitted.

Could not convert to Palo Alto Cortex XDR: xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name.

Verify this query against your own telemetry before deploying it — a converted rule is a starting point, not a tuned detection.

Conversion reportwindows / process_creation → Palo Alto Cortex XDR0 fields mapped · 1 unmapped · 1 construct unsupportedFailed

Could not convert to Palo Alto Cortex XDR: xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name.

Profile

Matched on product + category

Unmapped fields

This target validates column names against the schema.

  • OriginalFileNamenot in the target schema

    xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name.

    cortex-docs.paloaltonetworks.com

Know the right column? Tell us and we will add it.

Unsupported constructs

  • FatalField unmapped on a strict schema

    OriginalFileName

    xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name.

    No query was emitted.

Coverage

  1. selection_imgdropped
  2. selection_cliexpressed

1 / 2 conditions expressed

Engine 1.0.12026-09-09Rule licensed NOASSERTION

Worked examples on Palo Alto Cortex XDR

Real published rules run through the same engine as the tool above — including the ones it cannot take whole.

  1. Base64 Encoding Via Built-In Windows Utilitywindows / process_creationFailed

    Sigma

    title: Base64 Encoding Via Built-In Windows Utility
    id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a built-in utility being asked to
        base64-encode a file, which is a common way to stage data before moving it off a host.
        The flag is written out in both its dash and slash spellings, because the utility
        accepts either and a rule that names only one misses half the invocations.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.collection
        - attack.t1560.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\certutil.exe'
            - OriginalFileName: 'CertUtil.exe'
        selection_cli:
            CommandLine|contains:
                - '-encode'
                - '/encode'
        condition: all of selection_*
    falsepositives:
        - Administrative scripts that legitimately encode files
    level: medium
    

    Palo Alto Cortex XDR · XQL

    Could not convert to Palo Alto Cortex XDR: xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name.

    Could not convert to Palo Alto Cortex XDR: xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name. 1/2 conditions

  2. PowerShell Download Cradle On The Command Linewindows / process_creationClean

    Sigma

    title: PowerShell Download Cradle On The Command Line
    id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a
        remote payload is fetched and executed in one command. It exercises a value list under a
        single field, which every backend has to expand into its own OR form.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.execution
        - attack.t1059.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_fetch:
            CommandLine|contains:
                - '.DownloadString('
                - '.DownloadFile('
                - 'Invoke-WebRequest '
                - 'Invoke-RestMethod '
        selection_run:
            CommandLine|contains:
                - '| IEX'
                - 'IEX ('
                - 'Invoke-Expression'
        condition: all of selection_*
    falsepositives:
        - Installers and package managers that fetch and run their own payloads
    level: high
    

    Palo Alto Cortex XDR · XQL

    dataset = xdr_data
    | filter event_type = PROCESS and event_sub_type = PROCESS_START
    | filter ((action_process_image_command_line = "*.DownloadString(*" or action_process_image_command_line = "*.DownloadFile(*" or action_process_image_command_line = "*Invoke-WebRequest *" or action_process_image_command_line = "*Invoke-RestMethod *") and (action_process_image_command_line = "*| IEX*" or action_process_image_command_line = "*IEX (*" or action_process_image_command_line = "*Invoke-Expression*"))

    Every condition converted cleanly to Palo Alto Cortex XDR XQL. 2/2 conditions

  3. Registry Import With A Suspicious Pathwindows / process_creationFailed

    Sigma

    title: Registry Import With A Suspicious Path
    id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a registry import whose argument does
        not look like an ordinary file path. It exercises a regular expression alongside a `not`
        filter, so the report has both a regex to check against the target's engine and a negated
        branch to place.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1112
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\regedit.exe'
            - OriginalFileName: 'REGEDIT.EXE'
        selection_cli:
            CommandLine|contains: '.reg'
            CommandLine|re: ':[^ \\]'
        filter_flags:
            CommandLine|contains|windash:
                - ' -e '
                - ' -a '
        condition: all of selection_* and not filter_flags
    falsepositives:
        - Scripted registry maintenance
    level: high
    

    Palo Alto Cortex XDR · XQL

    Could not convert to Palo Alto Cortex XDR: xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name.

    Could not convert to Palo Alto Cortex XDR: xdr_data carries original-filename columns only for other actors — actor_ (the creating parent), causality_actor_ (the causality-group owner) and os_actor_ prefixes — not for the created process, so this strict target refuses rather than matching a different process's name. 2/3 conditions

  4. File Copy Through The Print Utilitywindows / process_creationClean

    Sigma

    title: File Copy Through The Print Utility
    id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the print utility being used to copy an
        executable rather than to print. It exercises `startswith` together with `contains|all`, where
        several substrings must all appear in one field.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1218
    logsource:
        category: process_creation
        product: windows
    detection:
        selection:
            Image|endswith: '\print.exe'
            CommandLine|startswith: 'print'
            CommandLine|contains|all:
                - '/D'
                - '.exe'
        filter_self:
            CommandLine|contains: 'print.exe'
        condition: selection and not filter_self
    falsepositives:
        - Printing a file whose name ends in .exe
    level: medium
    

    Palo Alto Cortex XDR · XQL

    dataset = xdr_data
    | filter event_type = PROCESS and event_sub_type = PROCESS_START
    | filter (action_process_image_path = "*\print.exe" and action_process_image_command_line = "print*" and action_process_image_command_line = "*/D*" and action_process_image_command_line = "*.exe*" and ((action_process_image_command_line = null or not (action_process_image_command_line = "*print.exe*"))))

    Every condition converted cleanly to Palo Alto Cortex XDR XQL. 2/2 conditions

  5. Scheduled Task Created From A Temp Pathwindows / process_creationClean

    Sigma

    title: Scheduled Task Created From A Temp Path
    id: 9d24a3ee-8a1b-4f26-b90f-4a71e2c85d17
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects schtasks.exe registering a task whose
        command line points into a temp directory, a common persistence shape. It exercises the
        bread-and-butter Sigma form — several selections ANDed by the condition — with no exotic
        modifiers, so it converts on every shipped target.
    author: HuntRule Team
    date: 2026-08-11
    tags:
        - attack.persistence
        - attack.t1053.005
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            Image|endswith: '\schtasks.exe'
        selection_create:
            CommandLine|contains: '/create'
        selection_path:
            CommandLine|contains:
                - '\AppData\Local\Temp\'
                - '\Windows\Temp\'
        condition: all of selection_*
    falsepositives:
        - Installers registering update tasks from their extraction directory
    level: medium
    

    Palo Alto Cortex XDR · XQL

    dataset = xdr_data
    | filter event_type = PROCESS and event_sub_type = PROCESS_START
    | filter (action_process_image_path = "*\schtasks.exe" and action_process_image_command_line = "*/create*" and (action_process_image_command_line = "*\AppData\Local\Temp\*" or action_process_image_command_line = "*\Windows\Temp\*"))

    Every condition converted cleanly to Palo Alto Cortex XDR XQL. 3/3 conditions

  6. LSASS Memory Dump Via Comsvcswindows / process_creationClean

    Sigma

    title: LSASS Memory Dump Via Comsvcs
    id: 6a95c2d4-1e08-4f7b-9d52-8c41e7b30a96
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the comsvcs.dll MiniDump export being
        invoked through rundll32 to dump process memory, a common LSASS credential-theft technique.
        It exercises `endswith` against the image path together with `contains|all` on one field.
    author: HuntRule Team
    date: 2026-08-10
    tags:
        - attack.credential-access
        - attack.t1003.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            Image|endswith: '\rundll32.exe'
        selection_cli:
            CommandLine|contains|all:
                - 'comsvcs'
                - 'MiniDump'
        condition: all of selection_*
    falsepositives:
        - Administrators legitimately capturing a process dump with comsvcs
    level: high
    

    Palo Alto Cortex XDR · XQL

    dataset = xdr_data
    | filter event_type = PROCESS and event_sub_type = PROCESS_START
    | filter (action_process_image_path = "*\rundll32.exe" and action_process_image_command_line = "*comsvcs*" and action_process_image_command_line = "*MiniDump*")

    Every condition converted cleanly to Palo Alto Cortex XDR XQL. 2/2 conditions

What to know about Palo Alto Cortex XDR XQL

XQL is one language across Cortex XDR and Cortex XSIAM, but it reads two different schemas, and the choice matters more than the syntax. This converter emits the raw xdr_data dataset with its actor-prefixed columns rather than the normalized XDM data model, for a reason worth stating plainly: on a process event the raw model is unambiguous — action_process_* is the process that was created and actor_* is the parent that created it — while XDM's source/target split for the same event is applied inconsistently even by Palo Alto's own community tooling. A converter that guesses that split emits queries that run and describe the wrong process. The raw form is also the only one a BIOC rule accepts.

Every query opens with dataset = xdr_data and pins the event population the way Palo Alto's own example does — filter event_type = PROCESS and event_sub_type = PROCESS_START, with the enum tokens unquoted, because quoting them matches nothing. The rule body becomes its own filter stage, fully parenthesised: XQL's boolean precedence is not documented anywhere, and a query whose meaning depends on an undocumented precedence table is not one to schedule.

This is a strict target and its coverage is deliberately citation-bound: Windows process creation, registry set/event, image load and network connection, with each event population and each mapped column cited to Palo Alto's own documentation — and file events left out on purpose, because only the write sub-type token is publicly documented and scoping to it alone would silently miss file-create rows. A field whose Cortex value cannot be verified without a live tenant — User's exact value form, Sysmon process GUIDs, the integer IntegrityLevel against Sigma's 'High' — is refused with the field named, and so is a field the dataset genuinely does not carry, like the created process's OriginalFileName; the report states the vendor-documented reason in both cases. Case matters too: XQL matching is case-insensitive by default, which matches Sigma, but the setting is query-global — a rule that demands per-predicate case sensitivity is answered with a warning, not a silent change of meaning.

Palo Alto Cortex XDR XQL reference →

How it works

  1. Step 1

    Paste the rule

    Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.

  2. Step 2

    Pick your SIEM

    Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.

  3. Step 3

    Read the report

    The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.

  4. Step 4

    Verify, then deploy

    Run it against your own telemetry in audit mode before it alerts on anything.

Questions

Paste the Sigma rule into the tool on this page and press Convert. It returns XQL for Palo Alto Cortex XDR, the log-source profile it matched, the field map it applied, and anything Palo Alto Cortex XDR cannot express. Free, no sign-up.

Both — XQL is one language across the two products; what differs is the available data. The query targets the xdr_data dataset, which exists wherever a Cortex agent reports, so it runs unchanged in XDR's Query Builder and XSIAM's.

Because the raw dataset's process roles are documented and unambiguous: action_process_* is the created process, actor_* its parent. XDM's source/target assignment for process events is not settled even in Palo Alto's own tooling, and a BIOC rule only accepts xdr_data anyway. An XDM output may follow as a separate, verified surface.

Usually a field whose Cortex value cannot be verified against official documentation — User's value form, a Sysmon GUID, or the integer integrity level against Sigma's string values. This strict target names the field and refuses rather than emitting a query that runs and silently matches nothing.

It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.

The other pair

The same tool, with a different target preselected.

Every rule in the detection catalog is written in Sigma, so any of them converts to Palo Alto Cortex XDR here.