Mostafa Moradian·5d agoThe State of RSigmaA tour of what one Rust binary does for detection engineering today, and where it is headed
Mostafa Moradian·May 25Cloud Detection at Scale on a LaptopHow RSigma streams 1.9 million CloudTrail events through a community IR playbook
Mostafa Moradian·May 12Wiring Live Threat Intel into Sigma Detection with Dynamic PipelinesTurning public threat feeds into live detection without rewriting a single rule
Mostafa Moradian·May 5Security Observability with RSigma and the LGTM StackConverting Sigma Rules to Dynamic Grafana Alerts
InITNEXTbyMostafa Moradian·Apr 29Building a Detection Layer on PostgreSQL with Sigma RulesHow RSigma turns 3,800+ community detection rules into SQL queries for TimescaleDBA response icon1A response icon1
InITNEXTbyMostafa Moradian·Apr 24Streaming Logs to RSigma for Real-Time DetectionTurning Four Routine Okta Detections into One Critical Alert
InITNEXTbyMostafa Moradian·Mar 4Declarative Audit Log Collection from HTTP APIsIntroducing Helr: a Rust-based generic HTTP API log collector that turns YAML config into a resilient log pipeline
InITNEXTbyMostafa Moradian·Feb 24Pattern Detection and Correlation in JSON LogsIntroducing RSigma: a Rust toolkit for evaluating Sigma detection rules against JSON events without a SIEM
Mostafa Moradian·Dec 2, 2025GCP Canary TokensHow to create and monitor GCP service accounts as canary tokens
Mostafa Moradian·Nov 3, 2025Detection as CodeHow to Build an Automated Security Detection Pipeline with GitHub Actions, Sigma, Grafana and Loki