Sign in

Mostafa Moradian

@mosi.bsky.social
61 followers 56 following 114 posts

Lead Security Engineer at Tiger Data | Securing and shipping cool stuff

PostsRepliesMedia
Mostafa Moradian @mosi.bsky.social · 16h
RSigma v0.23.0 is out! 🚀 First, I'd like to thank Meghdad Shamsaei for building RSTIX. Second, I'd like to thank Théo Foucher for finding a bug. Third, I'd like to thank Avishai Gonen and Yotam Perkal for reporting a vulnerability in RSigma MCP server. Release notes: github.com/timescale/rs...
000
Mostafa Moradian @mosi.bsky.social · 28/09/2026
Sigma lets you write a detection once in YAML. RSigma lets you run it anywhere: a single open-source Rust binary that evaluates Sigma rules directly against your logs, no SIEM needed. The full SigmaHQ rule pack runs at about 700k events/s on eight threads. MIT licensed. Docs: rsigma.io
Diagram of how RSigma works. Sigma rules and logs (JSON, Syslog, CEF, EVTX, logfmt, OTLP) flow into the RSigma engine, which parses, compiles, matches and correlates. Outputs: real-time alerts, SIEM queries for hunting, and MCP and LSP support for AI agents and editors.
111
Mostafa Moradian @mosi.bsky.social · 16/09/2026
Fundamental security issues like SSRF can seem like already solved problems, until they aren't. Especially now, with the amazing progress we're seeing in specialized LLMs for cybersecurity. Project: github.com/timescale/re... Article: mostafa.dev/four-ssrf-by...
000
Mostafa Moradian @mosi.bsky.social · 10/09/2026
Detection engineering breaks at the seams: draft, hunt, test, triage. Different tools every time. RSigma v0.22.0 closes the loop in one binary: • exemplars + rule test • correlation drafting • hunt run on Postgres • operate-cycle MCP against a live daemon github.com/timescale/rs...
000
Mostafa Moradian @mosi.bsky.social · 08/09/2026
xk6-kafka v2.2.0 is out! 🎉 • Init consumer groups at end offsets -> tests consume only what they produce • Kerberos + GCP OAuth + Azure Entra scope override • hamba/avro migrated to Confluent maintained fork • Producer throughput regression fixed -> back to ~380k msgs/s github.com/mostafa/xk6-...
000
Mostafa Moradian @mosi.bsky.social · 07/09/2026
RSigma is now the only Sigma engine in the latest release of Rustinel. 🎉 Rustinel author added support for correlations and filters using RSigma. It not only detects one-off events, but also can correlate events over time to detect escalations. github.com/Karib0u/rust...
github.com
Release Rustinel v1.5.0 · Karib0u/rustinel
Rustinel 1.5.0: correlated detection, stronger fidelity Rustinel 1.5 makes Sigma detection more capable and the live sensor pipeline more resilient. RSigma is now the single Sigma engine, with corr...
000
Mostafa Moradian @mosi.bsky.social · 03/09/2026
Excited to share that my talk has been accepted for Linux Security Summit Europe 2026! 🎉 I'll be speaking in Prague on October 8. See you in Prague! 🇨🇿 Session details: lsseu2026.sched.com/event/2WHc4
lsseu2026.sched.com
Linux Security Summit Europe 2026: Detection Engineering with RSigma - Most...
View more about this event at Linux Security Summit Europe 2026
000
Mostafa Moradian @mosi.bsky.social · 31/08/2026
Built with RSigma: rsigma.io#welcome-to-r...
000
Mostafa Moradian @mosi.bsky.social · 06/08/2026
You can try the latest version of RSigma MCP directly in your browser against the entire Sigma rules repository on Glama.ai. No need to install anything! glama.ai/mcp/servers/... These tools are provided: rsigma.io/guide/mcp-se...
000
Mostafa Moradian @mosi.bsky.social · 06/08/2026
RSigma is on this week in Rust newsletter: this-week-in-rust.org/blog/2026/08...
this-week-in-rust.org
This Week in Rust 663 · This Week in Rust
000
Mostafa Moradian @mosi.bsky.social · 05/08/2026
Most detection engines get slow the moment you load the real rule pack. RSigma v0.21.0 is out, and it now keeps the full pack and still keeps up. Repo: github.com/timescale/rs... Release notes: github.com/timescale/rs...
github.com
GitHub - timescale/rsigma: A complete Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, MCP and LSP servers :crab:
A complete Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, MCP and LSP servers :crab: - timescale/rsigma
010
Mostafa Moradian @mosi.bsky.social · 31/07/2026
I overhauled RSigma's performance on real-world SigmaHQ workloads, increasing the routed Windows daemon’s throughput from roughly 14.5k to 754.8k events per second on eight performance cores. Sound candidate indexing delivered 13-22.8x single-core gains: rsigma.io/guide/perfor...
rsigma.io
Performance Tuning - RSigma
000
Mostafa Moradian @mosi.bsky.social · 27/07/2026
RSigma is a complete Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, MCP and LSP servers. Repo: github.com/timescale/rs... GHA: github.com/timescale/rs... Docs: rsigma.io
000
Mostafa Moradian @mosi.bsky.social · 22/07/2026
Your best detections are stuck in one vendor's query language. RSigma v0.20.0 runs both ways: paste an Elastic/Lucene query, get back portable Sigma YAML. Plus a new IR engine, a TAXII 2.1 client, and cloud log auto-routing. Rust, single binary, open source. github.com/timescale/rs...
Before-and-after architecture diagram titled "RSigma v0.20.0: the IR backbone." Before (v0.19): Sigma YAML flows through a Parser, then fans out to four consumers (eval, PostgreSQL, LynxDB, Fibratus) that each re-resolve modifiers. After (v0.20): a single central IR (HIR) hub takes Sigma rules and, newly, SIEM queries, and feeds eval, byte-identical convert backends, an HIR cache, and a new reverse-to-Sigma path.
000
Mostafa Moradian @mosi.bsky.social · 22/07/2026
RSigma is now listed under Security Tools on awesome-rust: github.com/rust-unoffic...
github.com
GitHub - rust-unofficial/awesome-rust: A curated list of Rust code and resources.
A curated list of Rust code and resources. Contribute to rust-unofficial/awesome-rust development by creating an account on GitHub.
021
Mostafa Moradian @mosi.bsky.social · 13/07/2026
Hand-writing detection rules from a blank file is the slowest part of the job. RSigma v0.19.0 is out, taking the Rust Sigma engine from "here are some suspicious events" to "here's a tested draft rule". Feedback and testers very welcome. Release notes: github.com/timescale/rs...
010
Mostafa Moradian @mosi.bsky.social · 06/07/2026
The last State of RSigma promised to close the detection engineering loop. It closed. Part two follows one detection around it: drafted from real events, gated in CI, caught in production, judged, measured, and hunted into the next rule. Seven stations, one binary. mostafa.dev/the-state-of...
Two interlocking circles labeled Engineer and Operate around RSigma. Engineer: Author (rule draft, lint, ADS metadata, LSP, MCP), Test (explain, backtest, pipeline diff), Deploy (rsigma-action CI gate, hot-reload, signed builds). Operate: Detect (daemon, correlation, schema routing), Alert & Triage (enrichment, risk, dedup, webhooks), Measure (ATT&CK coverage, DeTT&CT visibility, scorecard, hygiene). Hunt (backend convert, sigma-cli delegation) bridges back: findings feed new rules.
000
Mostafa Moradian @mosi.bsky.social · 01/07/2026
10,000 alerts is not a detection strategy. RSigma v0.18.0 takes the Rust Sigma engine from "a rule fired" to "an alert worth reading": • Alert pipeline • Risk-based alerting • Triage feedback loop • Rule hygiene, schema and logsource routing, STIX 2.1 support and more github.com/timescale/rs...
010
Mostafa Moradian @mosi.bsky.social · 29/06/2026
RSigma has a GitHub Action for detection-as-code now, which uses the capabilities released in RSigma v0.17.0 last week. github.com/timescale/rs... To showcase these capabilities, I just published the 7th article in RSigma series: mostafa.dev/detection-as...
000
Mostafa Moradian @mosi.bsky.social · 23/06/2026
Anyone can write a detection rule. The real question is: can you prove it works? RSigma v0.17.0 turns detection from a guessing game into an engineering loop. Write rules. Measure them. Tune the noisy ones. Retire the dead ones. github.com/timescale/rs...
000
Mostafa Moradian @mosi.bsky.social · 16/06/2026
Your SIEM's rules, running in real time, in a tiny Rust binary, anywhere you want. RSigma isn't a SIEM, and that's exactly the point. mostafa.dev/the-state-of...
mostafa.dev
The State of RSigma
A tour of what one Rust binary does for detection engineering today, and where it is headed
000
Mostafa Moradian @mosi.bsky.social · 15/06/2026
Detection-as-Code, now native in AI coding agents. RSigma v0.16.0 adds an MCP server: point Cursor, Claude Code, or any MCP client at it and your agent can parse, lint, validate, evaluate, convert, and fix Sigma rules as typed tools, getting structured JSON. github.com/timescale/rs...
210
Mostafa Moradian @mosi.bsky.social · 11/06/2026
RSigma v0.15.0 is out, focused on new conversion targets and Sigma extensions. 🚀 Highlights: • Fibratus backend • Array matching • Correlation window modes Release notes: github.com/timescale/rs...
The RSigma logo, an orange and black tiger-striped lowercase "r" and Greek sigma monogram above the wordmark "RSigma", with the tagline "Complete Sigma Detection Toolkit: Parser, Linter, Evaluator, Correlation Engine, Conversion Framework, Streaming Daemon and LSP Server" beneath it on a white background.
000
Mostafa Moradian @mosi.bsky.social · 10/06/2026
My 3rd SEP (dynamic correlation windows) was rejected: windowing is a backend concern. RSigma ships it anyway: SEP: github.com/SigmaHQ/sigm... RSigma implementation: github.com/timescale/rs...
github.com
SEP: Dynamic Time Windows for Correlation Rules (sliding, tumbling, session) · Issue #214 · SigmaHQ/sigma-specification
Author(s) Mostafa Moradian SEP Type New Detection Logic (correlation types, aggregation functions) (Secondary: New Rule Fields, since it adds the window and gap attributes to the correlation sectio...
000
Mostafa Moradian @mosi.bsky.social · 08/06/2026
My 3rd proposal to the Sigma specification is up for review. Feedback is more than welcome! github.com/SigmaHQ/sigm...
github.com
SEP: Dynamic Time Windows for Correlation Rules (sliding, tumbling, session) · Issue #214 · SigmaHQ/sigma-specification
Author(s) Mostafa Moradian SEP Type New Detection Logic (correlation types, aggregation functions) (Secondary: New Rule Fields, since it adds the window and gap attributes to the correlation sectio...
000
Mostafa Moradian @mosi.bsky.social · 05/06/2026
One of the biggest releases of RSigma is out! 🚀 It includes layered YAML configuration, structured output and lots of overdue maintenance. Thanks to Fabian Wosar for contributing a nice feature to the linter. Repo: github.com/timescale/rs... Release notes: github.com/timescale/rs...
github.com
000
Mostafa Moradian @mosi.bsky.social · 03/06/2026
My second proposal to Sigma specification is up for review and feedback is much appreciated: github.com/SigmaHQ/sigm...
github.com
SEP: Rule-Level Specification Version Declaration · Issue #213 · SigmaHQ/sigma-specification
SEP: Rule-Level Specification Version Declaration Relates to: sigma-specification SEP #212 (Array Matching in Sigma), sigma-specification Discussion #106. Spun out of SEP #212. The mechanism was ra...
010
Mostafa Moradian @mosi.bsky.social · 02/06/2026
This is RSigma:
010
Mostafa Moradian @mosi.bsky.social · 01/06/2026
I am contributing the macOS port to Rustinel: github.com/Karib0u/rust...
github.com
GitHub - Karib0u/rustinel: Open-source endpoint detection engine for Windows and Linux using ETW, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
Open-source endpoint detection engine for Windows and Linux using ETW, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts. - Karib0u/rustinel
010
Mostafa Moradian @mosi.bsky.social · 01/06/2026
I guess I'm an influencer now. Don't believe me? The receipts are public: github.com/SigmaHQ/pySi...
github.com
Add processing pipeline modifier to obtain placeholder replacements from external data sources · Issue #470 · SigmaHQ/pySigma
Inspired by @mostafa's work in RSigma, external data sources would also be useful in pySigma's conversion use case. This should be implemented as new processing transformations for different types ...
110
Mostafa Moradian @mosi.bsky.social · 31/05/2026
Based on the previous work and discussions on the Sigma Specification and the RSigma project, I created a Sigma Enhancement Proposal for Array Matching in Sigma. Please read and provide feedback. github.com/SigmaHQ/sigm...
github.com
Issue · SigmaHQ/sigma-specification
Sigma rule specification. Contribute to SigmaHQ/sigma-specification development by creating an account on GitHub.
000
Mostafa Moradian @mosi.bsky.social · 26/05/2026
RSigma v0.13.0 is out. Here's a sneak peek: 1. Post-evaluation enrichment. 2. Server-side TLS on the daemon API. 3. Field observability. 4. A unified EvaluationResult library API 5. Detached dynamic sources via a new --source flag. github.com/timescale/rs...
github.com
Release v0.13.0 · timescale/rsigma
TL;DR RSigma v0.13.0 is the "post-evaluation enrichment, server-side TLS, and field observability" release: Post-evaluation enrichment between engine.evaluate() and the sinks: four primitives (tem...
010
Mostafa Moradian @mosi.bsky.social · 25/05/2026
My sixth blog post about RSigma is out. In this one, I walk through how it detects suspicious events across 1.9M CloudTrail records. As always, feedback is welcome and much appreciated. mostafa.dev/cloud-detect...
000
Mostafa Moradian @mosi.bsky.social · 20/05/2026
RSigma v0.12.0 is out! 🎉 It contains improved daemon and CLI observability, fast Sigma rule loading, reorganized set of CLI subcommands, full-on documentation, improved test reliability and deps version bumps. Release notes: github.com/timescale/rs... Documentation: timescale.github.io/rsigma/
github.com
Release v0.12.0 · timescale/rsigma
TL;DR RSigma v0.12.0 is the
000
Mostafa Moradian @mosi.bsky.social · 18/05/2026
Detection Studio added support for real-time Sigma rule evaluation against sample data using RSigma: Website: detection.studio GitHub repo: github.com/northsh/dete... RSigma: github.com/timescale/rs...
020
Mostafa Moradian @mosi.bsky.social · 14/05/2026
Just shipped RSigma v0.11.0, the biggest eval engine update yet. 𝐇𝐢𝐠𝐡𝐥𝐢𝐠𝐡𝐭𝐬: • Matcher optimizer • Opt-in bloom filter prefilter • Opt-in cross-rule Aho-Corasick prefilter • Security hardening • Many more All optimizations are backward-compatible. github.com/srdnlen/rsig...
github.com
010
Mostafa Moradian @mosi.bsky.social · 12/05/2026
I just published my newest article, and the fifth in my RSigma series: “Wiring Live Threat Intel into Sigma Detection with Dynamic Pipelines” Dynamic pipelines let you turn public threat feeds into live detections without rewriting a single Sigma rule. mostafa.dev/wiring-live-...
000
Mostafa Moradian @mosi.bsky.social · 08/05/2026
RSigma v0.10.0, the "dynamic pipelines" release, is out. 🚀 What's new: • Dynamic Sigma Pipelines • Native EVTX input • 14 cargo-fuzz harnesses • Pipeline hot-reload and two builtin pipelines Release notes: github.com/timescale/rs... Contributions and feedback are welcome.
github.com
Release v0.10.0 · timescale/rsigma
TL;DR RSigma v0.10.0 is the "dynamic pipelines" release: Dynamic Sigma Pipelines: declare HTTP, command, file, and NATS sources inside pipeline YAML, with template expansion, include directives, T...
010
Mostafa Moradian @mosi.bsky.social · 05/05/2026
In my new article, I cover an E2E security observability solution using RSigma, LGTM stack and more. The core technique is creating a single Grafana Alerting rule with dynamic labels, allowing metric labels to be extracted and reported as separate alert instances. mostafa.dev/security-obs...
010
Mostafa Moradian @mosi.bsky.social · 04/05/2026
RSigma v0.9.0 is released! 🚀 • Production-grade NATS JetStream • Native OpenTelemetry log ingestion • LynxDB conversion backend • Field catalog • Structured exit codes for CI/CD scripting • Per-rule Prometheus metric labels • Comprehensive E2E test suite github.com/timescale/rs...
github.com
Release v0.9.0 · timescale/rsigma
TL;DR RSigma v0.9.0 is one of the largest releases yet: Production-grade NATS JetStream with at-least-once delivery, authentication and TLS, dead-letter queues, replay from offset or timestamp, co...
010
Mostafa Moradian @mosi.bsky.social · 29/04/2026
What if Sigma detection rules were just SQL? RSigma now converts 3,800+ SigmaHQ rules to native PostgreSQL queries. JSONB, views, TimescaleDB continuous aggregates, temporal correlation; all from YAML. No SIEM. Just psql, pg_cron, and Grafana. mostafa.dev/building-a-d...
mostafa.dev
Building a Detection Layer on PostgreSQL with Sigma Rules
How RSigma turns 3,800+ community detection rules into SQL queries for TimescaleDB
010
Mostafa Moradian @mosi.bsky.social · 28/04/2026
RSigma v0.8.0 is out! New conversion engine turns Sigma detection rules into backend-native queries. First backend: PostgreSQL/TimescaleDB, with no equivalent in pySigma. Multi-arch Docker images, one-to-many field mapping, and full filter parity. github.com/timescale/rs...
github.com
Release v0.8.0 · timescale/rsigma
TL;DR RSigma v0.8.0 is the "rule conversion" release. A new rsigma-convert crate transforms Sigma rules into backend-native query strings through a pluggable Backend trait. The first production bac...
000
Mostafa Moradian @mosi.bsky.social · 24/04/2026
I wrote a new blog post, where I streamed events to RSigma with four SigmaHQ Okta rules, and watched it correlate individual detections into a single critical alert. Each detection alone? Noise. All four from the same actor in 30 minutes? Incident. mostafa.dev/streaming-lo...
mostafa.dev
Streaming Logs to RSigma for Real-Time Detection
Turning Four Routine Okta Detections into One Critical Alert
020
Mostafa Moradian @mosi.bsky.social · 23/04/2026
RSigma v0.7.0, the "any log format", is out! The Sigma detection engine now ingests JSON, syslog, logfmt, CEF, and plain text with auto-detection. 1M+ events/sec on JSON, 10M+/sec on plain text. Inspired by Sigma Engine by Sigma HQ. github.com/timescale/rs...
github.com
Release v0.7.0 · timescale/rsigma
TL;DR RSigma v0.7.0 is the "any log format" release. The evaluation engine now operates on a generic Event trait instead of raw JSON, a new rsigma-runtime library crate decouples the streaming pipe...
000
Mostafa Moradian @mosi.bsky.social · 18/03/2026
My project, RSigma, and the associated blog post are published in Zack Allen's latest newsletter, Detection Engineering Weekly. 🎉 www.detectionengineering.net/p/dew-149-ro...
011
Mostafa Moradian @mosi.bsky.social · 04/03/2026
I just published a new article about a project I've been working on past couple of weeks: mostafa.dev/declarative-...
mostafa.dev
Declarative Audit Log Collection from HTTP APIs
Introducing Helr: a Rust-based generic HTTP API log collector that turns YAML config into a resilient log pipeline
010
Mostafa Moradian @mosi.bsky.social · 24/02/2026
What if jq could hunt threats, too? mostafa.dev/fab16334e4ee
mostafa.dev
Pattern Detection and Correlation in JSON Logs
Introducing RSigma: a Rust toolkit for evaluating Sigma detection rules against JSON events without a SIEM
000
Mostafa Moradian @mosi.bsky.social · 17/02/2026
Over the past couple of weeks I've been busy cooking something in Rust. A generic HTTP API log collector for audit trails: github.com/timescale/helr And a parser, linter, evaluator and backend for Sigma in Rust along with an experimental LSP: github.com/timescale/rs...
000
Mostafa Moradian @mosi.bsky.social · 10/12/2025
xk6-kafka v1.2.0 is out! 🚀 This release brings an updated k6 baseline, a new Avro implementation, better precision and resiliency around time handling, balancer functions in JS, plus a handful of quality-of-life and security linting fixes. github.com/mostafa/xk6-...
010
Mostafa Moradian @mosi.bsky.social · 02/12/2025
I just published a new article on GCP canary tokens by turning Google Cloud service accounts into high-signal tripwires. mostafa.dev/gcp-canary-t...
mostafa.dev
GCP canary tokens
How to create and monitor GCP service accounts as canary tokens
000