alirezaaminzadeh/sigmaforge-rule-generator

TEXT GENERATIONPricing:Input $0.04 / Cached $0.008 / Output $0.08Concurrent Unit Cost:1Model Size:1.5BQuant:BF16Context Size:32kTool Calling:SupportedPublished:Aug 11, 2026License:mitArchitecture:Transformer Open Weights Featherless Exclusive Cold

The alirezaaminzadeh/sigmaforge-rule-generator is a 1.5 billion parameter instruction-tuned causal language model, based on Qwen/Qwen2.5-Coder-1.5B-Instruct, developed by the Aria AI Security Research Team. It specializes in drafting and repairing Sigma YAML detection rules from natural language descriptions, sample events, or broken rules. This model is optimized for cybersecurity detection engineering, achieving a 1.00 valid YAML rate and 0.92 Sigma schema pass rate for rule generation.

Loading preview...

SigmaForge Rule Generator Overview

The alirezaaminzadeh/sigmaforge-rule-generator is a specialized 1.5 billion parameter language model, fine-tuned from Qwen/Qwen2.5-Coder-1.5B-Instruct, designed for cybersecurity detection engineering. Developed by the Aria AI Security Research Team, its primary function is to generate and repair Sigma YAML detection rules.

Key Capabilities

  • Sigma Rule Generation: Drafts Sigma YAML rules from natural language descriptions of detections.
  • Rule Repair: Corrects broken Sigma rules based on validation errors.
  • Log-to-Rule Conversion: Creates expected Sigma rules from positive or negative event logs.
  • High Reliability: Achieves a 1.00 Valid YAML rate and 0.92 Sigma schema pass rate on held-out evaluation for description_to_sigma tasks.
  • Compilation Success: Demonstrates an 0.83 Splunk SPL compilation rate and 0.83 Elastic Lucene compilation rate, indicating generated rules are largely functional in common SIEMs.

Training and Usage Notes

The model was fine-tuned using LoRA on the alirezaaminzadeh/sigmaforge-detection-rules dataset, covering three supervised configurations: description_to_sigma, sigma_repair, and logs_to_sigma. While highly effective at generating valid and compilable Sigma YAML, its MITRE ATT&CK mapping F1 score is 0.14, suggesting that technique tagging is weaker. Users are advised to pair the model's output with the retrieval and pySigma validation loop available in the SigmaForge Space for robust, deployable rules, rather than using raw model output directly.