Sigma to Microsoft Sentinel
Paste a Sigma rule, get KQL for Sentinel. Free, no sign-up, with the table and column mapping shown.
Worked examples on Microsoft Sentinel
Real published rules run through the same engine as the tool above — including the ones it cannot take whole.
Base64 Encoding Via Built-In Windows Utilitywindows / process_creationDegraded
Sigma
title: Base64 Encoding Via Built-In Windows Utility id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 status: experimental description: | A sample rule for the huntrule.com converter. Detects a built-in utility being asked to base64-encode a file, which is a common way to stage data before moving it off a host. It exercises the `windash` modifier, where one flag has to be matched in both its dash and slash spellings. author: HuntRule Team date: 2026-08-01 tags: - attack.collection - attack.t1560.001 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\certutil.exe' - OriginalFileName: 'CertUtil.exe' selection_cli: CommandLine|contains|windash: '-encode' condition: all of selection_* falsepositives: - Administrative scripts that legitimately encode files level: medium license: DRL-1.1Microsoft Sentinel · KQL
// huntrule.com — sigma 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 — HuntRule Team — DRL-1.1 SecurityEvent | where EventID == 4688 | where CommandLine contains @'-encode' or CommandLine contains @'/encode' or CommandLine contains @'–encode' or CommandLine contains @'—encode' or CommandLine contains @'―encode'Converted to Microsoft Sentinel KQL with 1 note. 1 field had no verified mapping and was dropped from the query. 1 mapped field did not reach the query either: the clause holding it collapsed when a dropped predicate widened it. The query matches more than the original rule. 1/2 conditions
PowerShell Download Cradle On The Command Linewindows / process_creationClean
Sigma
title: PowerShell Download Cradle On The Command Line id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48 status: experimental description: | A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a remote payload is fetched and executed in one command. It exercises a value list under a single field, which every backend has to expand into its own OR form. author: HuntRule Team date: 2026-08-01 tags: - attack.execution - attack.t1059.001 logsource: category: process_creation product: windows detection: selection_fetch: CommandLine|contains: - '.DownloadString(' - '.DownloadFile(' - 'Invoke-WebRequest ' - 'Invoke-RestMethod ' selection_run: CommandLine|contains: - '| IEX' - 'IEX (' - 'Invoke-Expression' condition: all of selection_* falsepositives: - Installers and package managers that fetch and run their own payloads level: high license: DRL-1.1Microsoft Sentinel · KQL
// huntrule.com — sigma 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48 — HuntRule Team — DRL-1.1 SecurityEvent | where EventID == 4688 | where (CommandLine contains @'.DownloadString(' or CommandLine contains @'.DownloadFile(' or CommandLine contains @'Invoke-WebRequest ' or CommandLine contains @'Invoke-RestMethod ') and (CommandLine contains @'| IEX' or CommandLine contains @'IEX (' or CommandLine contains @'Invoke-Expression')Every condition converted cleanly to Microsoft Sentinel KQL. 2/2 conditions
Registry Import With A Suspicious Pathwindows / process_creationDegraded
Sigma
title: Registry Import With A Suspicious Path id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d status: experimental description: | A sample rule for the huntrule.com converter. Detects a registry import whose argument does not look like an ordinary file path. It exercises a regular expression alongside a `not` filter, so the report has both a regex to check against the target's engine and a negated branch to place. author: HuntRule Team date: 2026-08-01 tags: - attack.defense-evasion - attack.t1112 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\regedit.exe' - OriginalFileName: 'REGEDIT.EXE' selection_cli: CommandLine|contains: '.reg' CommandLine|re: ':[^ \\]' filter_flags: CommandLine|contains|windash: - ' -e ' - ' -a ' condition: all of selection_* and not filter_flags falsepositives: - Scripted registry maintenance level: high license: DRL-1.1Microsoft Sentinel · KQL
// huntrule.com — sigma 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d — HuntRule Team — DRL-1.1 SecurityEvent | where EventID == 4688 | where CommandLine contains @'.reg' and CommandLine matches regex @':[^ \\]' and (not(CommandLine contains @' -e ' or CommandLine contains @' /e ' or CommandLine contains @' –e ' or CommandLine contains @' —e ' or CommandLine contains @' ―e ' or CommandLine contains @' -a ' or CommandLine contains @' /a ' or CommandLine contains @' –a ' or CommandLine contains @' —a ' or CommandLine contains @' ―a '))Converted to Microsoft Sentinel KQL with 1 note. 1 field had no verified mapping and was dropped from the query. 1 mapped field did not reach the query either: the clause holding it collapsed when a dropped predicate widened it. The query matches more than the original rule. 2/3 conditions
File Copy Through The Print Utilitywindows / process_creationClean
Sigma
title: File Copy Through The Print Utility id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23 status: experimental description: | A sample rule for the huntrule.com converter. Detects the print utility being used to copy an executable rather than to print. It exercises `startswith` together with `contains|all`, where several substrings must all appear in one field. author: HuntRule Team date: 2026-08-01 tags: - attack.defense-evasion - attack.t1218 logsource: category: process_creation product: windows detection: selection: Image|endswith: '\print.exe' CommandLine|startswith: 'print' CommandLine|contains|all: - '/D' - '.exe' filter_self: CommandLine|contains: 'print.exe' condition: selection and not filter_self falsepositives: - Printing a file whose name ends in .exe level: medium license: DRL-1.1Microsoft Sentinel · KQL
// huntrule.com — sigma 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23 — HuntRule Team — DRL-1.1 SecurityEvent | where EventID == 4688 | where NewProcessName endswith @'\print.exe' and CommandLine startswith @'print' and CommandLine contains @'/D' and CommandLine contains @'.exe' and (CommandLine !contains @'print.exe')Every condition converted cleanly to Microsoft Sentinel KQL. 2/2 conditions
What to know about Microsoft Sentinel KQL
The hard part of Sigma to Sentinel is not the syntax, it is choosing the table. `SecurityEvent` carries 4688 process creation from the Security event log; `DeviceProcessEvents` carries it from Defender for Endpoint, with different column names and a different retention story. A rule that says `logsource: windows / process_creation` does not say which one you have, so the converter picks the higher-scoring profile and tells you what it picked and what else matched.
Kusto's string operators map onto Sigma's modifiers cleanly — `contains`, `startswith`, `endswith`, `has_any` — and `has_any` is what makes a multi-value Sigma selection compact rather than a chain of ORs. The one to watch is case: Kusto's `contains` is case-insensitive and `contains_cs` is not, and Sigma is case-insensitive by default. Where a rule asks for case sensitivity, the report says whether that survived.
Fields Sentinel keeps in the raw event XML rather than as columns are extracted rather than dropped, and the field map marks those rows so you can see the cost before you schedule the rule.
How it works
- Step 1
Paste the rule
Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.
- Step 2
Pick your SIEM
Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.
- Step 3
Read the report
The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.
- Step 4
Verify, then deploy
Run it against your own telemetry in audit mode before it alerts on anything.
Questions
Paste the Sigma rule into the tool on this page and press Convert. It returns KQL for Microsoft Sentinel, the log-source profile it matched, the field map it applied, and anything Microsoft Sentinel cannot express. Free, no sign-up.
SecurityEvent for Windows event-log rules, DeviceProcessEvents where the rule is Defender-shaped. The report says which profile matched and what the runners-up scored, so you can switch if your workspace collects the other one.
Kusto's contains and has operators are case-insensitive, matching Sigma's default. Where a rule explicitly asked for case sensitivity and it could not be kept, the report records it as a widened clause.
It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.
The other pair
The same tool, with a different target preselected.
- Sigma to SplunkSPLSearch Processing Language against a CIM-normalised index.
- Sigma to Microsoft Defender XDRKQLKusto over the Defender advanced-hunting Device* schema.
- Sigma to Elastic SecurityKQLKibana Query Language over ECS-mapped indices — the Kibana default.
- Sigma to Elastic SecurityLuceneLucene query_string — required when the rule uses a regular expression.
- Sigma to CrowdStrike FalconCQLCrowdStrike Query Language for Falcon LogScale and Next-Gen SIEM.
Every rule in the detection catalog is written in Sigma, so any of them converts to Microsoft Sentinel here.