Sigma to IBM QRadar
Paste a Sigma rule, get an AQL search for on-prem QRadar SIEM — with the custom-property dependencies named. Free, no sign-up.
Worked examples on IBM QRadar
Real published rules run through the same engine as the tool above — including the ones it cannot take whole.
Base64 Encoding Via Built-In Windows Utilitywindows / process_creationDegraded
Sigma
title: Base64 Encoding Via Built-In Windows Utility id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 status: experimental description: | A sample rule for the huntrule.com converter. Detects a built-in utility being asked to base64-encode a file, which is a common way to stage data before moving it off a host. The flag is written out in both its dash and slash spellings, because the utility accepts either and a rule that names only one misses half the invocations. author: HuntRule Team date: 2026-08-01 tags: - attack.collection - attack.t1560.001 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\certutil.exe' - OriginalFileName: 'CertUtil.exe' selection_cli: CommandLine|contains: - '-encode' - '/encode' condition: all of selection_* falsepositives: - Administrative scripts that legitimately encode files level: mediumIBM QRadar · AQL
SELECT * FROM events WHERE devicetype=12 AND (("Process Path" ILIKE '%\certutil.exe' OR Filename ILIKE 'CertUtil.exe') AND (Command ILIKE '%-encode%' OR Command ILIKE '%/encode%')) LAST 24 HOURSConverted to IBM QRadar AQL with 1 note. 1/2 conditions
PowerShell Download Cradle On The Command Linewindows / process_creationClean
Sigma
title: PowerShell Download Cradle On The Command Line id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48 status: experimental description: | A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a remote payload is fetched and executed in one command. It exercises a value list under a single field, which every backend has to expand into its own OR form. author: HuntRule Team date: 2026-08-01 tags: - attack.execution - attack.t1059.001 logsource: category: process_creation product: windows detection: selection_fetch: CommandLine|contains: - '.DownloadString(' - '.DownloadFile(' - 'Invoke-WebRequest ' - 'Invoke-RestMethod ' selection_run: CommandLine|contains: - '| IEX' - 'IEX (' - 'Invoke-Expression' condition: all of selection_* falsepositives: - Installers and package managers that fetch and run their own payloads level: highIBM QRadar · AQL
SELECT * FROM events WHERE devicetype=12 AND ((Command ILIKE '%.DownloadString(%' OR Command ILIKE '%.DownloadFile(%' OR Command ILIKE '%Invoke-WebRequest %' OR Command ILIKE '%Invoke-RestMethod %') AND (Command ILIKE '%| IEX%' OR Command ILIKE '%IEX (%' OR Command ILIKE '%Invoke-Expression%')) LAST 24 HOURSEvery condition converted cleanly to IBM QRadar AQL. 2/2 conditions
Registry Import With A Suspicious Pathwindows / process_creationDegraded
Sigma
title: Registry Import With A Suspicious Path id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d status: experimental description: | A sample rule for the huntrule.com converter. Detects a registry import whose argument does not look like an ordinary file path. It exercises a regular expression alongside a `not` filter, so the report has both a regex to check against the target's engine and a negated branch to place. author: HuntRule Team date: 2026-08-01 tags: - attack.defense-evasion - attack.t1112 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\regedit.exe' - OriginalFileName: 'REGEDIT.EXE' selection_cli: CommandLine|contains: '.reg' CommandLine|re: ':[^ \\]' filter_flags: CommandLine|contains|windash: - ' -e ' - ' -a ' condition: all of selection_* and not filter_flags falsepositives: - Scripted registry maintenance level: highIBM QRadar · AQL
SELECT * FROM events WHERE devicetype=12 AND (("Process Path" ILIKE '%\regedit.exe' OR Filename ILIKE 'REGEDIT.EXE') AND Command ILIKE '%.reg%' AND Command MATCHES '.*(?::[^ \\]).*' AND ((Command IS NULL OR NOT(Command ILIKE '% -e %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% /e %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% –e %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% —e %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% ―e %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% -a %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% /a %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% –a %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% —a %'))) AND ((Command IS NULL OR NOT(Command ILIKE '% ―a %')))) LAST 24 HOURSConverted to IBM QRadar AQL with 1 note. 2/3 conditions
File Copy Through The Print Utilitywindows / process_creationClean
Sigma
title: File Copy Through The Print Utility id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23 status: experimental description: | A sample rule for the huntrule.com converter. Detects the print utility being used to copy an executable rather than to print. It exercises `startswith` together with `contains|all`, where several substrings must all appear in one field. author: HuntRule Team date: 2026-08-01 tags: - attack.defense-evasion - attack.t1218 logsource: category: process_creation product: windows detection: selection: Image|endswith: '\print.exe' CommandLine|startswith: 'print' CommandLine|contains|all: - '/D' - '.exe' filter_self: CommandLine|contains: 'print.exe' condition: selection and not filter_self falsepositives: - Printing a file whose name ends in .exe level: mediumIBM QRadar · AQL
SELECT * FROM events WHERE devicetype=12 AND ("Process Path" ILIKE '%\print.exe' AND Command ILIKE 'print%' AND Command ILIKE '%/D%' AND Command ILIKE '%.exe%' AND ((Command IS NULL OR NOT(Command ILIKE '%print.exe%')))) LAST 24 HOURSEvery condition converted cleanly to IBM QRadar AQL. 2/2 conditions
Scheduled Task Created From A Temp Pathwindows / process_creationClean
Sigma
title: Scheduled Task Created From A Temp Path id: 9d24a3ee-8a1b-4f26-b90f-4a71e2c85d17 status: experimental description: | A sample rule for the huntrule.com converter. Detects schtasks.exe registering a task whose command line points into a temp directory, a common persistence shape. It exercises the bread-and-butter Sigma form — several selections ANDed by the condition — with no exotic modifiers, so it converts on every shipped target. author: HuntRule Team date: 2026-08-11 tags: - attack.persistence - attack.t1053.005 logsource: category: process_creation product: windows detection: selection_img: Image|endswith: '\schtasks.exe' selection_create: CommandLine|contains: '/create' selection_path: CommandLine|contains: - '\AppData\Local\Temp\' - '\Windows\Temp\' condition: all of selection_* falsepositives: - Installers registering update tasks from their extraction directory level: mediumIBM QRadar · AQL
SELECT * FROM events WHERE devicetype=12 AND ("Process Path" ILIKE '%\schtasks.exe' AND Command ILIKE '%/create%' AND (Command ILIKE '%\AppData\Local\Temp\%' OR Command ILIKE '%\Windows\Temp\%')) LAST 24 HOURSEvery condition converted cleanly to IBM QRadar AQL. 3/3 conditions
LSASS Memory Dump Via Comsvcswindows / process_creationClean
Sigma
title: LSASS Memory Dump Via Comsvcs id: 6a95c2d4-1e08-4f7b-9d52-8c41e7b30a96 status: experimental description: | A sample rule for the huntrule.com converter. Detects the comsvcs.dll MiniDump export being invoked through rundll32 to dump process memory, a common LSASS credential-theft technique. It exercises `endswith` against the image path together with `contains|all` on one field. author: HuntRule Team date: 2026-08-10 tags: - attack.credential-access - attack.t1003.001 logsource: category: process_creation product: windows detection: selection_img: Image|endswith: '\rundll32.exe' selection_cli: CommandLine|contains|all: - 'comsvcs' - 'MiniDump' condition: all of selection_* falsepositives: - Administrators legitimately capturing a process dump with comsvcs level: highIBM QRadar · AQL
SELECT * FROM events WHERE devicetype=12 AND ("Process Path" ILIKE '%\rundll32.exe' AND Command ILIKE '%comsvcs%' AND Command ILIKE '%MiniDump%') LAST 24 HOURSEvery condition converted cleanly to IBM QRadar AQL. 2/2 conditions
What to know about IBM QRadar AQL
Every query comes out in IBM's own shape: SELECT * FROM events WHERE devicetype=12 AND your conditions, ending with an explicit LAST 24 HOURS. The timeframe is not decoration — an AQL query without one silently searches only the last five minutes of data, and it runs without any error to tell you so. The devicetype filter is the log-source-type id from IBM's own Sigma tooling; QRadar has no separate Sysmon type, so Windows Security Event Log and Sysmon rules share it by design.
The honest difficulty with QRadar is that almost none of a Windows rule's fields are normalized columns. Command lines, process paths and usernames live in Custom Event Properties shipped by IBM's App Exchange content packs — Properties Dictionary plus Microsoft Windows Custom Properties — and IBM documents the failure mode this creates: a query naming a property that is not installed and enabled runs cleanly and returns nothing. That is why the report lists the content packs beside the query, and why a Sigma field with no vendor-published property is refused by name instead of being guessed at.
Case is handled with the documented operators rather than the common shortcut. Sigma matching is case-insensitive by default; AQL's LIKE is documented case-sensitive and ILIKE is its insensitive twin, so plain equality and substring predicates all ride ILIKE, and only a |cased modifier produces LIKE. A value containing a literal % or _ cannot be expressed in LIKE at all — AQL documents no escape for its wildcards — so those predicates become anchored IMATCHES regular expressions instead of silently over-matching every user profile path.
How it works
- Step 1
Paste the rule
Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.
- Step 2
Pick your SIEM
Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.
- Step 3
Read the report
The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.
- Step 4
Verify, then deploy
Run it against your own telemetry in audit mode before it alerts on anything.
Questions
Paste the Sigma rule into the tool on this page and press Convert. It returns AQL for IBM QRadar, the log-source profile it matched, the field map it applied, and anything IBM QRadar cannot express. Free, no sign-up.
Usually a Custom Event Property. Most Windows fields in the query are content-pack properties such as "Process Path" and "Command", and IBM documents that an uninstalled or unenabled property runs without error and returns nothing. Install Properties Dictionary and Microsoft Windows Custom Properties from the IBM App Exchange, and verify each property is enabled. Also check the LAST clause — without one, AQL searches only the last five minutes.
On-premises QRadar SIEM, 7.5 and 7.6. QRadar's SaaS products were divested to Palo Alto Networks and reached end of life in April 2026, while IBM ships and supports the on-prem product into the 2030s. The AQL operator surface is identical across 7.5 and 7.6.
Sigma string matching is case-insensitive by default. IBM documents LIKE as case-sensitive and ILIKE as its case-insensitive twin, but never documents the case behaviour of = at all — so plain equality is spelled with ILIKE, which is exact equality when the value carries no wildcard, and |cased produces LIKE. Nothing rests on an undocumented comparison.
It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.
The other pair
The same tool, with a different target preselected.
- SplunkSPLSearch Processing Language against a CIM-normalised index.Open schemaConvert
- Splunk — Raw IndexSPLSearch Processing Language against raw indexed events without assuming CIM normalisation.Open schemaConvert
- Microsoft SentinelKQLKusto over Sentinel's analytics tables.Open schemaConvert
- Microsoft Sentinel ASIMASIM KQLKusto over ASIM's unifying parsers, not raw tables.Closed schemaConvert
- Microsoft Defender XDRKQLKusto over the Defender advanced-hunting Device* schema.Closed schemaConvert
- Elastic SecurityKQLKibana Query Language over ECS-mapped indices — the Kibana default.Open schemaConvert
- Elastic SecurityLuceneLucene query_string — required when the rule uses a regular expression.Open schemaConvert
- Elastic SecurityES|QLES|QL pipeline query over ECS indices — case-insensitive by construction, unlike KQL and Lucene.Closed schemaConvert
- CrowdStrike FalconCQLCrowdStrike Query Language for Falcon LogScale and Next-Gen SIEM.Open schemaConvert
- SentinelOnePowerQueryPowerQuery (S1QL 2.0) for Event Search and Singularity Data Lake, on the native EDR schema.Closed schemaConvert
- Palo Alto Cortex XDRXQLXQL over the Cortex agent's xdr_data dataset, scoped by event type.Closed schemaConvert
Carbon Black CloudPlatform SearchLucene query for Carbon Black Cloud Processes Search (Windows process creation).Closed schemaConvert
Carbon Black EDRProcess SearchToken search over the on-premises EDR product, where the process columns hold file names rather than paths.Open schemaConvert
Google Security OperationsUDM SearchA UDM Search predicate list for Investigation > SIEM Search, scoped by the normalised event type. Not a YARA-L detection rule, which is a different artifact.Closed schemaConvert- Sumo Logic Cloud SIEMRules expressionThe expression half of a Cloud SIEM rule, over the normalised schema.Closed schemaConvert
- Rapid7Rapid7 InsightIDRLEQLLog Entry Query Language, with case-insensitive operators throughout.Closed schemaConvert
- GraylogSearchGraylog search syntax, with regexes where wildcards are blocked.Open schemaConvert
- OpenSearchLuceneLucene query_string over an ECS-mapped index. Covers Amazon OpenSearch Service.Open schemaConvert
- OpenSearch PPLPPLPiped Processing Language over an ECS-mapped index. Covers Amazon OpenSearch Service.Open schemaConvert
- GrafanaGrafana LokiLogQLLogQL over a stream selector you supply. Loki indexes labels, not line contents, so the selector is yours to fill in.Open schemaConvert
- SQLiteSQLA SELECT over your own table. No regex: SQLite defines none by default.Open schemaConvert
- DFIRZircoliteSQLiteSQL against Zircolite's flattened logs table, with regex support.Open schemaConvert
Every rule in the detection catalog is written in Sigma, so any of them converts to IBM QRadar here.