SASVAAI/Gemma-4-26B-A4B-sigma-rules
SASVAAI/Gemma-4-26B-A4B-sigma-rules is a 26 billion parameter Gemma 4-based language model developed by SASVA AI Model Cognition Labs (MCL) Team, fine-tuned for generating Sigma detection rules in YAML format from plain-language requirements. It leverages a mixture-of-experts architecture with approximately 4 billion active parameters per token and has a context length of 32768 tokens. This model specializes in cybersecurity detection engineering, converting natural language descriptions into structured Sigma rules for SIEM systems.
Loading preview...
Model Overview
SASVAAI/Gemma-4-26B-A4B-sigma-rules is a specialized 26 billion parameter language model, developed by the SASVA AI Model Cognition Labs (MCL) Team, built upon Google's Gemma-4-26B-A4B-it base model. It is specifically fine-tuned to generate Sigma detection rules in YAML format from plain-language security requirements. The model utilizes a mixture-of-experts architecture, with roughly 4 billion active parameters per token, and supports a context length of 32768 tokens.
Key Capabilities
- Sigma Rule Generation: Translates detection requirements, including log source, ATT&CK technique IDs, and known false positives, into YAML-formatted Sigma rules.
- Specialized Fine-tuning: Trained using QLoRA (4-bit NF4 base, bf16 compute) on a dataset of 3,371 SigmaHQ rules, focusing on the
title,description,logsource,detection,falsepositives,level, andtagsfields. - High Parse Rate: Achieves a 69.3% parse rate for valid Sigma rules under pySigma 1.5.1 and a 69.3% Splunk SPL compilation rate, indicating its ability to produce syntactically correct outputs.
Intended Use Cases
- Detection Engineering: Assists detection engineers by drafting initial Sigma rules for review, validation, and adaptation.
- Cybersecurity Automation: Streamlines the process of converting security requirements into actionable detection logic for Security Information and Event Management (SIEM) systems.
Limitations
While effective, users should be aware that approximately 31% of outputs may fail to parse as valid Sigma rules, often due to SigmaConditionError. Additionally, about 25% of generations can be runaway outputs, requiring max_new_tokens to be capped. The model's evaluation focuses on wording overlap (ROUGE-L 0.592) rather than the functional correctness of the generated rules against actual events. It is crucial to validate all generated rules with pySigma before deployment.