Skip to content

docs: add ATR (Agent Threat Rules) to the list of tools supporting Sigma#6015

Merged
nasbench merged 2 commits into
SigmaHQ:masterfrom
eeee2345:atr-tools-doc
Jun 11, 2026
Merged

docs: add ATR (Agent Threat Rules) to the list of tools supporting Sigma#6015
nasbench merged 2 commits into
SigmaHQ:masterfrom
eeee2345:atr-tools-doc

Conversation

@eeee2345

Copy link
Copy Markdown
Contributor

Summary of the Pull Request

Adds ATR (Agent Threat Rules) to the list of projects and products that use or integrate Sigma rules in the README.

ATR is an MIT-licensed open detection rule format for AI agent security threats. Authoring shape is similar to Sigma but targeted at LLM input/output, MCP tool calls, and agent context windows. The reference CLI exports ATR rules to Sigma format via atr convert sigma, so any Sigma-consuming pipeline can ingest ATR-derived rules directly.

Repository: https://github.com/Agent-Threat-Rule/agent-threat-rules
License: MIT
DOI: 10.5281/zenodo.19178002

Single-line addition to keep the change minimal and easy to review. Happy to adjust placement, wording, or formatting to match maintainer preference.

Changelog

docs: add ATR (Agent Threat Rules) to the list of tools supporting Sigma

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

Signed-off-by: Adam Lin <adam@agentthreatrule.org>
@github-actions github-actions Bot added Review Needed The PR requires review Maintenance Related to additions and update of the repository features labels May 16, 2026
@nasbench nasbench merged commit f7f93ec into SigmaHQ:master Jun 11, 2026
@nasbench nasbench added this to the Sigma-June-Release milestone Jun 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Maintenance Related to additions and update of the repository features Review Needed The PR requires review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants