| @@ -9,6 +9,8 @@ Every rule here converts cleanly to **Splunk SPL**, **Elastic ES|QL**, and **Mic | ||
| Sentinel / Defender KQL**, and is tagged to MITRE ATT&CK so coverage is something you can | ||
| measure instead of guess at. | ||
| + |  | |
| + | ||
| ## Why | ||
| A detection written in one SIEM's query language is stranded there. Writing it in Sigma |