Downloads · 30 days
0
nemanisri/grounded-sigma-compiler
grounded-sigma-compiler is a text generation model from nemanisri. Use it when you need the model to write or continue text. It is set up for mlx. The card lists the license as other.
[!IMPORTANT] Documentation-only preview: Adapter weights are not currently available for public download. This adapter was trained using attributed SigmaHQ rules governed by DRL-1.1. Clarification has been requested f…
Downloads · 30 days
0
Access
Public
Updated Aug 2, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.json75.9 KB · 70%
From the Hugging Face model README
[!IMPORTANT] Documentation-only preview: Adapter weights are not currently available for public download. This adapter was trained using attributed SigmaHQ rules governed by DRL-1.1. Clarification has been requested from SigmaHQ concerning distribution of LoRA adapter weights. Weights will be released only after the licensing requirements are confirmed.
A narrow MLX LoRA adapter that converts a supplied, grounded detection specification into a single Sigma-style JSON object. It is a compiler, not an autonomous detection author: the caller supplies the detection logic, telemetry fields, log source, ATT&CK mappings, false positives, and severity.
mlx-community/Qwen2.5-7B-Instruct-4bitThe adapter must be loaded with its exact base model. adapters.safetensors
alone is not a standalone model.
Requires Apple silicon, macOS, and Python 3.9 or newer.
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install --upgrade pip
python3 -m pip install -r requirements.txt
From this release directory:
python3 inference.py \
--input example_input.json \
--adapter adapter \
--output generated_rule.json
jq . generated_rule.json
The first run downloads the approximately 4.3 GB base model. The wrapper accepts exactly these grounded input fields:
title, description, logsource, detection, attack_techniques,
false_positives, severity
It rejects invalid JSON, missing or extra input fields, and model output that
changes grounded content. A successful result contains only those fields plus
"requires_validation": true.
Checkpoint 50 was evaluated against rule families excluded from training.
| Evaluation | Base strict pass | Adapter strict pass |
|---|---|---|
| Held-out Sigma rules (45) | 19/45 (42.2%) | 43/45 (95.6%) |
| Synthetic robustness cases (10) | 6/10 (60.0%) | 10/10 (100%) |
On the 45-rule set, the adapter achieved 100% exact detection logic and 100% exact ATT&CK mapping preservation. Its two strict failures were description-text normalization differences. The robustness suite included Unicode, nested conditions, modifiers, null values, escaping, and instruction-like strings embedded as data.
These are small, curated evaluations and are not evidence of general Sigma generation ability. Retest after changing the base model, adapter, prompt, dependency versions, or inference code.
The base Qwen2.5-7B-Instruct model is published under Apache-2.0; the MLX conversion is mlx-community/Qwen2.5-7B-Instruct-4bit.
Training examples were derived from rules in SigmaHQ/sigma, whose detection content is published under the Detection Rule License 1.1. Credit belongs to SigmaHQ and the individual rule contributors. Source rule IDs and paths should remain available in dataset provenance records.
License status: publication review required. Before uploading the adapter or training data, confirm the Detection Rule License attribution and distribution requirements for this use, retain notices required by the base model, and choose an explicit license for original wrapper code and documentation. Do not label the complete release Apache-2.0 solely because the base model uses that license. This note is not legal advice.
Verify packaged files from the release directory:
shasum -a 256 -c SHA256SUMS