Sigma detection rules created by analysts at NTT Security for the Samurai MDR service.
These rules were initially made for NTT Security's internal CIM standard which normalizes logs from multiple vendors. While we've made an effort to convert the fields to the same ones used in SigmaHQ's repository, there are some that will require custom mapping if you want to use these rules.