{{ notification }}
SIGMA RULE BUILDER
✓ valid {{ lint.errors.length }} error{{ lint.errors.length !== 1 ? 's' : '' }}
{{ aiPanelHeading('title') }}
{{ aiState.title.text || aiLoadingLabel('title') }}
{{ aiState.title.error }}
{{ t }}
{{ aiPanelHeading('describe') }}
{{ aiState.describe.text || aiLoadingLabel('describe') }}
{{ aiState.describe.error }}
{{ d }}
{{ aiPanelHeading('falsepositives') }}
{{ aiState.falsepositives.text || aiLoadingLabel('falsepositives') }}
{{ aiState.falsepositives.error }}
{{ fp }}

Presets fill the fields below and suggest detection field names.

Available fields for this logsource:

{{ f }}

Keywords match against full log event text (no field binding).

{{ aiPanelHeading('detection') }}
{{ aiState.detection.text || aiLoadingLabel('detection') }}
{{ aiState.detection.error }}
{{ aiPanelHeading('tags') }}
{{ aiState.tags.text || aiLoadingLabel('tags') }}
{{ aiState.tags.error }}
MITRE ATT&CK ENTERPRISE — v14.1
{{ tac.label }} {{ tac.visibleCount }}
✕ {{ e }}
⚠ {{ w }}
✓ Rule looks good
{{ aiPanelHeading('explain') }}
{{ aiState.explain.error }}
{{ aiPanelHeading('review') }} {{ aiState.review.score }}/10
{{ aiState.review.rawText || aiLoadingLabel('review') }}
{{ aiState.review.error }}
{{ yamlOutput }}
QUERY CONVERTER Best-effort — always review before use
{{ converterOutput }}

⚠ {{ converterNote }}

LIVE PREVIEW
✕ {{ e }}
{{ yamlOutput }}