Scikit-learn
Joblib
English
tfidf_logistic_logsource_classifier
cybersecurity
sigma
detection-engineering
mitre-attack
gradio
enterprise
Instructions to use alirezaaminzadeh/sigmaforge-logsource-classifier with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Scikit-learn
How to use alirezaaminzadeh/sigmaforge-logsource-classifier with Scikit-learn:
from huggingface_hub import hf_hub_download import joblib model = joblib.load( hf_hub_download("alirezaaminzadeh/sigmaforge-logsource-classifier", "sklearn_model.joblib") ) # only load pickle files from sources you trust # read more about it here https://skops.readthedocs.io/en/stable/persistence.html - Notebooks
- Google Colab
- Kaggle
| license: mit | |
| language: | |
| - en | |
| tags: | |
| - cybersecurity | |
| - sigma | |
| - detection-engineering | |
| - mitre-attack | |
| - gradio | |
| - enterprise | |
| library_name: sklearn | |
| # SigmaForge Logsource Classifier | |
| TF-IDF + Logistic Regression classifier that maps detection hypotheses to Sigma `logsource` fields (product, service, category). | |
| ## Intended Use | |
| - Classify log source for Sigma rule generation pipeline | |
| - Not for production SIEM routing without retraining on your environment | |
| ## Training | |
| Trained on synthetic hypothesis ↔ logsource pairs derived from SigmaHQ rule corpus. | |
| ## Limitations | |
| - CPU-only inference | |
| - Best performance on Windows/Sysmon/DNS hypotheses | |
| - Heuristic fallback when model artifacts unavailable | |