Lucene

Sigma to Elastic Lucene

Paste a Sigma rule, get a Lucene query_string for Elastic Security — including the rules KQL cannot express. Free, no sign-up.

certutil
Tab indents · Shift+Tab outdents · Esc then Tab leaves the field28 lines · 906 B
Elastic Security

Target not listed? Tell us which →
1 caveat
event.category:process AND event.type:start AND ((process.executable:*\\certutil.exe OR process.pe.original_file_name:CertUtil.exe) AND (process.command_line:*\-encode* OR process.command_line:*\/encode* OR process.command_line:*–encode* OR process.command_line:*—encode* OR process.command_line:*―encode*))

logs-endpoint.events.process-*, logs-windows.sysmon_operational-*, logs-system.security*, winlogbeat-*An Elastic query carries no index: the scope lives on the detection rule object, in 'index: []' or 'data_view_id'. Set index to the patterns your deployment ships this log source to — conventionally logs-endpoint.events.process-*, logs-windows.sysmon_operational-*, logs-system.security*, winlogbeat-* — and set language to 'lucene' with type 'query'.

1 line · 313 B2/2 conditions

Verify this query against your own telemetry before deploying it — a converted rule is a starting point, not a tuned detection.

Conversion reportwindows / process_creation → Elastic Security3 fields mapped · 1 construct unsupportedDegraded

Converted to Elastic Security Lucene with 1 note.

Profile

Matched on product + category

Field map

Sigma fieldTarget fieldSource
CommandLineprocess.command_linegithub.com
Imageprocess.executablegithub.com
OriginalFileNameprocess.pe.original_file_namegithub.com

Unsupported constructs

  • DroppedCase sensitivity narrowed

    CASE_SEMANTICS

    Case sensitivity on Elastic is a property of the field mapping, not of the query language. ECS types these fields as 'keyword' or 'wildcard', which match byte-exactly including case, and neither KQL nor Lucene has an operator that changes it — so a Sigma rule's conventional case-insensitivity is not preserved and a value whose case differs from the logged one will not match. Sigma's '|cased' modifier, by contrast, is honoured exactly.

    Narrowed to a case-SENSITIVE match: this target compares byte-exactly and the rule asked for insensitive, so a value whose case differs from the logged one will not match.

Coverage

  1. selection_imgexpressed
  2. selection_cliexpressed

2 / 2 conditions expressed

Engine 1.0.02026-08-02Rule licensed DRL-1.1

Worked examples on Elastic Security

Real published rules run through the same engine as the tool above — including the ones it cannot take whole.

  1. Base64 Encoding Via Built-In Windows Utilitywindows / process_creationDegraded

    Sigma

    title: Base64 Encoding Via Built-In Windows Utility
    id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a built-in utility being asked to
        base64-encode a file, which is a common way to stage data before moving it off a host.
        It exercises the `windash` modifier, where one flag has to be matched in both its dash
        and slash spellings.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.collection
        - attack.t1560.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\certutil.exe'
            - OriginalFileName: 'CertUtil.exe'
        selection_cli:
            CommandLine|contains|windash: '-encode'
        condition: all of selection_*
    falsepositives:
        - Administrative scripts that legitimately encode files
    level: medium
    license: DRL-1.1
    

    Elastic Security · Lucene

    event.category:process AND event.type:start AND ((process.executable:*\\certutil.exe OR process.pe.original_file_name:CertUtil.exe) AND (process.command_line:*\-encode* OR process.command_line:*\/encode* OR process.command_line:*–encode* OR process.command_line:*—encode* OR process.command_line:*―encode*))

    Converted to Elastic Security Lucene with 1 note. 2/2 conditions

  2. PowerShell Download Cradle On The Command Linewindows / process_creationDegraded

    Sigma

    title: PowerShell Download Cradle On The Command Line
    id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a
        remote payload is fetched and executed in one command. It exercises a value list under a
        single field, which every backend has to expand into its own OR form.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.execution
        - attack.t1059.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_fetch:
            CommandLine|contains:
                - '.DownloadString('
                - '.DownloadFile('
                - 'Invoke-WebRequest '
                - 'Invoke-RestMethod '
        selection_run:
            CommandLine|contains:
                - '| IEX'
                - 'IEX ('
                - 'Invoke-Expression'
        condition: all of selection_*
    falsepositives:
        - Installers and package managers that fetch and run their own payloads
    level: high
    license: DRL-1.1
    

    Elastic Security · Lucene

    event.category:process AND event.type:start AND ((process.command_line:*.DownloadString\(* OR process.command_line:*.DownloadFile\(* OR process.command_line:*Invoke\-WebRequest\ * OR process.command_line:*Invoke\-RestMethod\ *) AND (process.command_line:*\|\ IEX* OR process.command_line:*IEX\ \(* OR process.command_line:*Invoke\-Expression*))

    Converted to Elastic Security Lucene with 1 note. 2/2 conditions

  3. Registry Import With A Suspicious Pathwindows / process_creationDegraded

    Sigma

    title: Registry Import With A Suspicious Path
    id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a registry import whose argument does
        not look like an ordinary file path. It exercises a regular expression alongside a `not`
        filter, so the report has both a regex to check against the target's engine and a negated
        branch to place.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1112
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\regedit.exe'
            - OriginalFileName: 'REGEDIT.EXE'
        selection_cli:
            CommandLine|contains: '.reg'
            CommandLine|re: ':[^ \\]'
        filter_flags:
            CommandLine|contains|windash:
                - ' -e '
                - ' -a '
        condition: all of selection_* and not filter_flags
    falsepositives:
        - Scripted registry maintenance
    level: high
    license: DRL-1.1
    

    Elastic Security · Lucene

    event.category:process AND event.type:start AND ((process.executable:*\\regedit.exe OR process.pe.original_file_name:REGEDIT.EXE) AND process.command_line:*.reg* AND process.command_line:/.*:[^ \\].*/ AND (NOT (process.command_line:*\ \-e\ * OR process.command_line:*\ \/e\ * OR process.command_line:*\ –e\ * OR process.command_line:*\ —e\ * OR process.command_line:*\ ―e\ * OR process.command_line:*\ \-a\ * OR process.command_line:*\ \/a\ * OR process.command_line:*\ –a\ * OR process.command_line:*\ —a\ * OR process.command_line:*\ ―a\ *)))

    Converted to Elastic Security Lucene with 1 note. 3/3 conditions

  4. File Copy Through The Print Utilitywindows / process_creationDegraded

    Sigma

    title: File Copy Through The Print Utility
    id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the print utility being used to copy an
        executable rather than to print. It exercises `startswith` together with `contains|all`, where
        several substrings must all appear in one field.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1218
    logsource:
        category: process_creation
        product: windows
    detection:
        selection:
            Image|endswith: '\print.exe'
            CommandLine|startswith: 'print'
            CommandLine|contains|all:
                - '/D'
                - '.exe'
        filter_self:
            CommandLine|contains: 'print.exe'
        condition: selection and not filter_self
    falsepositives:
        - Printing a file whose name ends in .exe
    level: medium
    license: DRL-1.1
    

    Elastic Security · Lucene

    event.category:process AND event.type:start AND (process.executable:*\\print.exe AND process.command_line:print* AND process.command_line:*\/D* AND process.command_line:*.exe* AND (NOT process.command_line:*print.exe*))

    Converted to Elastic Security Lucene with 1 note. 2/2 conditions

What to know about Elastic Security Lucene

Lucene is the second query language Kibana accepts, and on this site it is not the alternative to KQL so much as the completion of it. KQL has no regular-expression operator; Lucene does. If your Sigma rule uses `|re`, this is the page that can answer it, and Elastic's own documentation points the same way.

Lucene's regular expressions are not PCRE and the differences bite immediately. A Lucene regexp is implicitly anchored to the whole field value, so a pattern that would match a substring elsewhere matches nothing here unless it is wrapped in `.*`. The shorthand classes are absent — no `\d`, `\w`, `\s` or `\b` — so a Sigma pattern using them has to be rewritten in terms of explicit character classes. The converter does that rewriting and tells you where it happened, because a regex that silently changed meaning is worse than one that failed loudly.

There is also a small set of characters Lucene reserves and does not let you escape at all, `<` and `>` among them. A Sigma value containing one cannot be expressed as a Lucene term, and the report says so rather than emitting a query that parses into something else. Everything else — reserved characters, quoting, the `AND` / `OR` / `NOT` operators, which Lucene requires in uppercase unlike KQL — is escaped and spelled for you.

Elastic Security Lucene reference →

How it works

  1. Step 1

    Paste the rule

    Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.

  2. Step 2

    Pick your SIEM

    Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.

  3. Step 3

    Read the report

    The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.

  4. Step 4

    Verify, then deploy

    Run it against your own telemetry in audit mode before it alerts on anything.

Questions

Paste the Sigma rule into the tool on this page and press Convert. It returns Lucene for Elastic Security, the log-source profile it matched, the field map it applied, and anything Elastic Security cannot express. Free, no sign-up.

Lucene anchors a regexp to the whole field value. A pattern that matches a substring in PCRE has to be wrapped in .* here. The converter does this, and the report says where it changed the pattern.

< and > cannot be escaped at all. A Sigma value containing one has no Lucene term form, so the conversion reports it rather than emitting a query that parses into something different from what the rule asked for.

It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.

The other pair

The same tool, with a different target preselected.

Every rule in the detection catalog is written in Sigma, so any of them converts to Elastic Security here.