KQL

Sigma to Microsoft Sentinel

Paste a Sigma rule, get KQL for Sentinel. Free, no sign-up, with the table and column mapping shown.

certutil
Tab indents · Shift+Tab outdents · Esc then Tab leaves the field28 lines · 906 B
Microsoft Sentinel

Target not listed? Tell us which →
2 caveats
// Target: Microsoft Sentinel (KQL) — engine 1.0.0 — 2026-08-02
// Profile: windows / process_creation → Microsoft Sentinel
// Coverage: 1/2 conditions
// dropped: OriginalFileName — Dropped the predicate; the query is broader than the rule.
// Verify against your own telemetry before deploying.
// huntrule.com — sigma 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 — HuntRule Team — DRL-1.1
SecurityEvent
| where EventID == 4688
| where CommandLine contains @'-encode' or CommandLine contains @'/encode' or CommandLine contains @'–encode' or CommandLine contains @'—encode' or CommandLine contains @'―encode'
4 lines · 316 B1/2 conditions

Verify this query against your own telemetry before deploying it — a converted rule is a starting point, not a tuned detection.

Conversion reportwindows / process_creation → Microsoft Sentinel1 field mapped · 2 unmapped · 1 construct unsupportedDegraded

Converted to Microsoft Sentinel KQL with 1 note. 1 field had no verified mapping and was dropped from the query. 1 mapped field did not reach the query either: the clause holding it collapsed when a dropped predicate widened it. The query matches more than the original rule.

Profile

Matched on product + category

Field map

Sigma fieldTarget fieldSource
CommandLineSecurityEvent.CommandLinelearn.microsoft.com

Unmapped fields

  • Imagemapped, but not in the query

    Another predicate in the same clause had no verified mapping and was dropped. Dropping widens, and a widened branch absorbs the OR it sits in, so this predicate was removed with it and the query does not constrain this field at all.

  • OriginalFileNamedropped — query broadened

    The SecurityEvent table (4688) does not carry the original-filename resource string.

    learn.microsoft.com

Know the right column? Tell us and we will add it.

Unsupported constructs

  • DroppedField unmapped, predicate dropped

    OriginalFileName

    The SecurityEvent table (4688) does not carry the original-filename resource string.

    Dropped the predicate; the query is broader than the rule.

Coverage

  1. selection_imgno longer matches the same events
  2. selection_cliexpressed

1 / 2 conditions expressed

Engine 1.0.02026-08-02Rule licensed DRL-1.1

Worked examples on Microsoft Sentinel

Real published rules run through the same engine as the tool above — including the ones it cannot take whole.

  1. Base64 Encoding Via Built-In Windows Utilitywindows / process_creationDegraded

    Sigma

    title: Base64 Encoding Via Built-In Windows Utility
    id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a built-in utility being asked to
        base64-encode a file, which is a common way to stage data before moving it off a host.
        It exercises the `windash` modifier, where one flag has to be matched in both its dash
        and slash spellings.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.collection
        - attack.t1560.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\certutil.exe'
            - OriginalFileName: 'CertUtil.exe'
        selection_cli:
            CommandLine|contains|windash: '-encode'
        condition: all of selection_*
    falsepositives:
        - Administrative scripts that legitimately encode files
    level: medium
    license: DRL-1.1
    

    Microsoft Sentinel · KQL

    // huntrule.com — sigma 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 — HuntRule Team — DRL-1.1
    SecurityEvent
    | where EventID == 4688
    | where CommandLine contains @'-encode' or CommandLine contains @'/encode' or CommandLine contains @'–encode' or CommandLine contains @'—encode' or CommandLine contains @'―encode'

    Converted to Microsoft Sentinel KQL with 1 note. 1 field had no verified mapping and was dropped from the query. 1 mapped field did not reach the query either: the clause holding it collapsed when a dropped predicate widened it. The query matches more than the original rule. 1/2 conditions

  2. PowerShell Download Cradle On The Command Linewindows / process_creationClean

    Sigma

    title: PowerShell Download Cradle On The Command Line
    id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a
        remote payload is fetched and executed in one command. It exercises a value list under a
        single field, which every backend has to expand into its own OR form.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.execution
        - attack.t1059.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_fetch:
            CommandLine|contains:
                - '.DownloadString('
                - '.DownloadFile('
                - 'Invoke-WebRequest '
                - 'Invoke-RestMethod '
        selection_run:
            CommandLine|contains:
                - '| IEX'
                - 'IEX ('
                - 'Invoke-Expression'
        condition: all of selection_*
    falsepositives:
        - Installers and package managers that fetch and run their own payloads
    level: high
    license: DRL-1.1
    

    Microsoft Sentinel · KQL

    // huntrule.com — sigma 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48 — HuntRule Team — DRL-1.1
    SecurityEvent
    | where EventID == 4688
    | where (CommandLine contains @'.DownloadString(' or CommandLine contains @'.DownloadFile(' or CommandLine contains @'Invoke-WebRequest ' or CommandLine contains @'Invoke-RestMethod ') and (CommandLine contains @'| IEX' or CommandLine contains @'IEX (' or CommandLine contains @'Invoke-Expression')

    Every condition converted cleanly to Microsoft Sentinel KQL. 2/2 conditions

  3. Registry Import With A Suspicious Pathwindows / process_creationDegraded

    Sigma

    title: Registry Import With A Suspicious Path
    id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a registry import whose argument does
        not look like an ordinary file path. It exercises a regular expression alongside a `not`
        filter, so the report has both a regex to check against the target's engine and a negated
        branch to place.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1112
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\regedit.exe'
            - OriginalFileName: 'REGEDIT.EXE'
        selection_cli:
            CommandLine|contains: '.reg'
            CommandLine|re: ':[^ \\]'
        filter_flags:
            CommandLine|contains|windash:
                - ' -e '
                - ' -a '
        condition: all of selection_* and not filter_flags
    falsepositives:
        - Scripted registry maintenance
    level: high
    license: DRL-1.1
    

    Microsoft Sentinel · KQL

    // huntrule.com — sigma 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d — HuntRule Team — DRL-1.1
    SecurityEvent
    | where EventID == 4688
    | where CommandLine contains @'.reg' and CommandLine matches regex @':[^ \\]' and (not(CommandLine contains @' -e ' or CommandLine contains @' /e ' or CommandLine contains @' –e ' or CommandLine contains @' —e ' or CommandLine contains @' ―e ' or CommandLine contains @' -a ' or CommandLine contains @' /a ' or CommandLine contains @' –a ' or CommandLine contains @' —a ' or CommandLine contains @' ―a '))

    Converted to Microsoft Sentinel KQL with 1 note. 1 field had no verified mapping and was dropped from the query. 1 mapped field did not reach the query either: the clause holding it collapsed when a dropped predicate widened it. The query matches more than the original rule. 2/3 conditions

  4. File Copy Through The Print Utilitywindows / process_creationClean

    Sigma

    title: File Copy Through The Print Utility
    id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the print utility being used to copy an
        executable rather than to print. It exercises `startswith` together with `contains|all`, where
        several substrings must all appear in one field.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1218
    logsource:
        category: process_creation
        product: windows
    detection:
        selection:
            Image|endswith: '\print.exe'
            CommandLine|startswith: 'print'
            CommandLine|contains|all:
                - '/D'
                - '.exe'
        filter_self:
            CommandLine|contains: 'print.exe'
        condition: selection and not filter_self
    falsepositives:
        - Printing a file whose name ends in .exe
    level: medium
    license: DRL-1.1
    

    Microsoft Sentinel · KQL

    // huntrule.com — sigma 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23 — HuntRule Team — DRL-1.1
    SecurityEvent
    | where EventID == 4688
    | where NewProcessName endswith @'\print.exe' and CommandLine startswith @'print' and CommandLine contains @'/D' and CommandLine contains @'.exe' and (CommandLine !contains @'print.exe')

    Every condition converted cleanly to Microsoft Sentinel KQL. 2/2 conditions

What to know about Microsoft Sentinel KQL

The hard part of Sigma to Sentinel is not the syntax, it is choosing the table. `SecurityEvent` carries 4688 process creation from the Security event log; `DeviceProcessEvents` carries it from Defender for Endpoint, with different column names and a different retention story. A rule that says `logsource: windows / process_creation` does not say which one you have, so the converter picks the higher-scoring profile and tells you what it picked and what else matched.

Kusto's string operators map onto Sigma's modifiers cleanly — `contains`, `startswith`, `endswith`, `has_any` — and `has_any` is what makes a multi-value Sigma selection compact rather than a chain of ORs. The one to watch is case: Kusto's `contains` is case-insensitive and `contains_cs` is not, and Sigma is case-insensitive by default. Where a rule asks for case sensitivity, the report says whether that survived.

Fields Sentinel keeps in the raw event XML rather than as columns are extracted rather than dropped, and the field map marks those rows so you can see the cost before you schedule the rule.

Microsoft Sentinel KQL reference →

How it works

  1. Step 1

    Paste the rule

    Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.

  2. Step 2

    Pick your SIEM

    Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.

  3. Step 3

    Read the report

    The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.

  4. Step 4

    Verify, then deploy

    Run it against your own telemetry in audit mode before it alerts on anything.

Questions

Paste the Sigma rule into the tool on this page and press Convert. It returns KQL for Microsoft Sentinel, the log-source profile it matched, the field map it applied, and anything Microsoft Sentinel cannot express. Free, no sign-up.

SecurityEvent for Windows event-log rules, DeviceProcessEvents where the rule is Defender-shaped. The report says which profile matched and what the runners-up scored, so you can switch if your workspace collects the other one.

Kusto's contains and has operators are case-insensitive, matching Sigma's default. Where a rule explicitly asked for case sensitivity and it could not be kept, the report records it as a widened clause.

It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.

The other pair

The same tool, with a different target preselected.

Every rule in the detection catalog is written in Sigma, so any of them converts to Microsoft Sentinel here.