Loading…
October 8, 2026 | Prague, Czechia
View More Details & Registration  |  Note: The schedule is subject to change.
You must be registered for Linux Security Summit Europe 2026 to participate in the sessions. Please visit the event registration page to purchase a ticket. 
Thursday October 8, 2026 16:55 - 17:40 CEST
Sigma is the open, vendor-neutral standard for detection rules, yet most Sigma tooling only translates rules into another vendor's query language. RSigma is a toolkit that evaluates Sigma directly against logs in real time: a parser, a compiled matcher, a stateful correlation engine, and a streaming daemon in one small static binary.

This is a working session on detection engineering for Linux. We take kernel-sourced telemetry (the audit subsystem, journald and syslog, and eBPF sensors), stream portable Sigma detections over it on the host, and correlate weak signals into high-fidelity alerts with a small footprint and no SIEM in the loop. Then we treat detections as code: lint, test against known-good/known-bad fixtures, measure ATT&CK coverage, and gate everything in CI.

Expect Rust internals, real auditd and eBPF events, live rules, and an honest account of what a self-contained engine should and should not own. Everything shown is open source and reproducible.
Speakers
avatar for Mostafa Moradian

Mostafa Moradian

Head of Security, Tiger Data
Mostafa Moradian is the Head of Security at TigerData, where he leads people and initiatives that strengthen the security posture across a global infrastructure. His work spans across large-scale security automation, open-source contributions and cross-functional engineering projects... Read More →
Thursday October 8, 2026 16:55 - 17:40 CEST
Chamber Hall (Floor 3)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link