To enable the Sigma rules, you want to navigate to the Add-ons
section and search for Sigma in the search bar.
Under the Organization
dropdown, select a tenant (organization) you want to subscribe to Sigma rules and click Subscribe
:
Please note that add-ons are applied on the per-tenant basis. If you have multiple organizations you want to subscribe to Sigma, you will need to subscribe each organization to the add-on separately.
You can also manage add-ons from the Subscriptions
menu under Billing
.
Tenants that have been subscribed to the add-on, will be marked with a green check mark in the Organization
dropdown.
Please note that some Sigma rules on Windows rely on Windows Event Logs that are not collected by LimaCharlie by default. In order to leverage these you will need to configure an automated collection of relevant Windows Event Logs through the Artifact Collection service.