Supplementary Data: SigmaHQ Detection Context Analysis for 'From Sharing to Acting: Standardizing Detection Context to Bridge the CTI Actionability Gap'.
收藏资源简介:
This dataset contains the supplementary materials supporting the systematic analysis of contextual metadata in SigmaHQ community detection rules reported in Scavotto, B., "From Sharing to Acting: Standardizing Detection Context to Bridge the CTI Actionability Gap" (submitted to ACM Digital Threats: Research and Practice, 2026). The deposit includes two files. The file sigma_analysis_results.csv contains rule-level coding results for a stratified random sample of 200 detection rules drawn from the SigmaHQ repository (commit accessed March 2026). Each row represents one rule and records its category, status, title, and coding against ten contextual elements: threat description, MITRE ATT&CK mapping, false positive guidance, severity, business context, response and triage guidance, detection confidence, data source requirements, author provenance, and version history. False positive guidance is coded as present, placeholder, trivial, or absent, distinguishing substantive content from non-informative entries such as "Unknown" or "Unlikely." The file sigma_analysis.py contains the Python script used to draw the stratified sample (random seed 42, proportional allocation by category with a minimum floor of five rules per category, restricted to stable and test status rules) and to code each rule against the ten contextual elements via automated YAML parsing. The script can be run against any local copy of the SigmaHQ repository to reproduce the sampling and coding process. Raw detection rules are not included in this deposit and should be obtained directly from the publicly available SigmaHQ repository at https://github.com/SigmaHQ/sigma.



